Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesCopyBotsEarn

Velocore Addresses $7M Hack In Postmortem, Offers 10% White Hat Bounty

CryptodailyCryptodaily2024/06/03 10:37
By:Amara Khatri

Table of Contents

  • Details Of The Hack
  • Exploit Postmortem
  • Velocore Reaches Out To Hacker

Decentralized exchange Velocore has addressed its recent hack in a postmortem. The exchange suffered an exploit that led to the loss of about $7 million.

The exchange has offered the hacker a 10% bug bounty but has yet to receive a response.

Details Of The Hack

The hack was orchestrated after the hacker exploited a vulnerability in the smart contracts controlling the decentralized exchange’s liquidity pools. The hacker was able to exploit the vulnerability in overflow logic. This allowed them to trick Velocore into turning a small withdrawal into a large deposit. The hacker then used a flash loan attack to drain the decentralized exchange’s “volatile pools” on zkSync Era and Linea. The Velocore team was able to safeguard its assets on Telos, and “stable pools” were not impacted. In a post on X, Velocore stated,

“We’ve identified the exploit mechanism and are setting up an on-chain negotiation process. A post-mortem article is in the works. Tracking the exploiter with clues left behind. More updates soon. Velocore on the Telos mainnet has not been affected, and we are working with the foundation while functionalities are frozen. We will provide guidance on safely withdrawing all funds in the future.”

Exploit Postmortem

In response to the hack, Velocore initiated an investigation and set up an on-chain negotiation process to retrieve the funds from the hacker. The decentralized exchange also shared an emergency notice after the hack, urging users to be cautious. It also halted all operations on the exchange and froze the stolen funds. However, despite these measures, the hacker was able to transfer a portion of the funds across chains to the Ethereum mainnet. Velocore wrote in its postmortem of the incident,

“Despite undergoing multiple audits and implementing preventive features to ensure security, this unexpected incident happened swiftly. We are deeply saddened and sincerely apologize to our users who have trusted us. Velocore has also disabled the logic flaw used in the exploit, eliminating the chance of a copycat attack.”

The team promised users it would provide another update on the incident soon. The hack also resulted in the Linea Layer2 network temporarily pausing block production to mitigate losses.

“Because other avenues of handling this exploit closed, our team halted the sequencer to prevent additional funds bridging out.”

Linea defended its decision to halt the chain, adding that its eventual goal was to remove the team’s ability to halt the network via decentralization.

“Most L2s, including Linea, still rely on centralized technical operations, which can be leveraged to protect ecosystem participants. Linea’s core value is a permissionless, censorship-resistant environment, so it was not a decision we took lightly.”

Velocore Reaches Out To Hacker

Meanwhile, Velocore has offered the hacker a 10% white hat bounty if the remainder of the stolen funds are returned by June 3, 8:00 UTC. While the hacker has yet to respond to the offer, they have already deposited 1700 ETH, worth around $7 million, into Tornado Cash, a cryptocurrency mixer. The decentralized exchange added that it had taken a snapshot of the blockchain prior to the incident and would come up with a compensation plan for its users.

“For those affected, we have taken a snapshot of the blockchain state prior to the incident. Once operations resume, we will implement an appropriate compensation plan to address the losses incurred to our users.”

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

Investment Disclaimer
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

You may also like

Shiba Inu (SHIB) vs. Ethereum: Analysts Explore Potential for 40x Gains

Coinedition2024/07/01 16:58

VeChain (VET) Surges 11% in a Week: Analysts Predict Further Gains

Coinedition2024/07/01 16:58

EU crypto traders urged to convert non-compliant stablecoins to regulated ones as MiCA framework takes effect

Quick Take EU stablecoin users are urged to convert non-compliant stablecoins to regulated ones as the bloc’s MiCA regulation goes live. The new regulations prohibit stablecoins from exceeding one million daily transactions used to pay for goods or services, whether settled off-chain or on-chain.

The Block2024/07/01 16:52

Mamori raises $5 million in Blockchain Capital-led seed funding

Quick Take The web3 security firm Mamori raised $5 million in seed funding led by the venture capital firm Blockchain Capital. Mamori aims to augment web3 security by developing an algorithm that can find issues in blockchain-based software.

The Block2024/07/01 16:49

‌Spot copy trading

More
AIOnline
AIOnline
insight1000/1000
9916.91%
ROI
Total profit $50576.23
WhaleGo_YouTube
WhaleGo_YouTube
insight500/500
1321.82%
ROI
Total profit $3838.06

Bot copy trading

More
Morgee
Morgee
insight69/150
$19751.22
Total profit
Total subscriber profits $-219.74
GoldenEgg
GoldenEgg
insight141/150
$8163.06
Total profit
Total subscriber profits $-284.87