The Aug. 3 hack of the Nomad token bridge was the fourth largest crypto hack in history. There, nearly $200 million worth of crypto assets were stolen from the platform. But not only the hack, but also the method behind it attracted a lot of attention.
The exploit was possible due to a smart contract vulnerability. In addition to the hacker, hundreds of other users also used these and took as much as possible with them. All they had to do was copy the transaction details used by the original hacker and enter their own wallet address. This event was later classified by many as a decentralized heist as regular community members were also involved.
The Nomad team later revealed to Cointelegraph that some of the people who were withdrawing funds acted benevolently to prevent the hackers from stealing all of the cryptocurrencies.
After the hack, crypto analytics firm BestBrokers determined that the first attack happened on August 1st. In this case, 400 Bitcoin ( BTC ) were stolen in four different transactions. The hackers then extracted 22,880 Ether ( ETH ), then moved on to the stablecoins worth over $107 million, and finally to the altcoins backed by the project.
The incident involved WBTC, Wrapped Ether (WETH), USD Coin ( USDC ), Frax (FRAX), Covalent Query Token (CQT), Hummingbird Governance Token (HBOT), IAGON (IAG), Dai ( DAI ), GeroWallet (GERO ), Card Starter (CARDS), Saddle DAO (SDL) and Charli3 (C3) tokens stolen from the bridge.
Some altcoins stolen from the platform have seen drops of as much as 94 percent. According to the analytics firm's data , the following altcoins saw the biggest drop after the hack:
The exploited smart contract vulnerability was previously highlighted in a security audit report by Quantstamp in the first week of June. The Nomad team responded that it was "virtually impossible to find the blank slate archetype".
The investigators believed the Nomad team misunderstood the issue at the time. Two months later, this same vulnerability resulted in nearly $200 million in losses.
Cointelegraph reached out to Nomad for comment on the discovery, and the team has since responded that the vulnerability identified by Quantstamp was different from the one that enabled the hack. The company also assured that it is actively working to return the money to users.
My Top PicksHoneygain - Passive earner that pays in BTC or PayPalMandalaExchange -The Best no KYC crypto Exchange!
BetFury - Play And Earn BFG for daily Bitcoin and ETH dividends!
Pipeflare - Faucet that pays in ZCash and Matic, Games pay in DAIWomplay - Mobile dApp gaming platform that rewards in EOS and BitcoinCointiply - The #1 Crypto Earning SiteTorum - Join the latest Social Network and earn TRM for Free!LiteCoinPay -The #1 FaucetPay earner for LitecoinLBRY/Odysee - YouTube Alternative that lets you earn Money by viewing videos!FaucetPay - The #1 Microwallet PlatformFREEBTC - The #1 FaucetPay earner for Satoshi'sFaucetCrypto - An earning/faucet site that pays out instantlyFireFaucet - An earning site that pays better for some than Cointiply
DogeFaucet - Dogecoin Faucet
xFaucet - BTC, ETH, LTC, Doge, Dash, Tron, DGB, BCH, BNB, ZEC, FEY - Claim every 5 minutes
Konstantinova - BTC, ETH, LTC, Doge, Dash, Tron, DGB, BNB, ZEC, USDT, FEY, 25 Claims Daily
Comments
Post a Comment