x
Black Bar Banner 1
x

Alert!  New Secured Wallets are installed! new Blog system with AI  power and auto blog curation coming soon  Alert! 

Ads by Markethive - View All
Blogs
The Blog Feed
Write a New Blog Post
Search Blog Status
Most Viewed
Most Recent
Most Shared
Alphabetical
Blog Main Menu
Markethive Blog (default)
All Blogs
My Blog Posts
Friends' Blogs
Blog Categories
All
Advertising
Blockchain & Cryptocurrency
Business Development
Diet & Weight Loss
Environmental
Health and Wellness
History and Culture
Home and Garden
Marketing
Mentoring & Training
Money & Finance
Other
Political
Prayer & Religion
Programming & Technical
Real Estate
Search Engine Optimization
Social Media
Spirituality
Sports & Recreation
Transport
Travel & Events
Website Design
Blogging Tools & Assets
My Blog Info
Members Subscribed to You
Blogs You Are Subscribed To
Website Widget
Wordpress Plugin

Hacker Steals $320 Million From Solana, Ethereum Bridge Wormhole

Posted by Andries Van Tonder on February 03, 2022 - 10:25am


Hacker Steals $320 Million From Solana, Ethereum Bridge Wormhole

Wormhole helps people move digital assets between Solana, Ethereum, and other blockchains.

By Jeff Benson

Wormhole, a protocol that allows users to move their tokens and NFTs between Solana and Ethereum, has confirmed that it suffered an exploit of 120,000 Wrapped Ethereum, worth over $320 million—higher than the $250 million originally suspected.

"ETH will be added over the next hours to ensure wETH is backed 1:1," it posted on Twitter, adding: "We are working to get the network back up quickly."

Earlier on Wednesday, a post on Wormhole's Twitter account noted the network was "down for maintenance" due to a "potential exploit." But by that point the exploit, pointed out by Paradigm security researcher samczsun, appeared to be real. A message on the Ethereum blockchain, purportedly from Wormhole, states: "We noticed that you were able to exploit the Solana VAA verification and mint tokens. We would like to offer you a whitehat agreement, and present you a bug bounty of $10 million for exploit details, and returning the wETH you have minted."

VAA stands for "validator action approval," and refers to the process by which transactions get approved.

The message means that Wormhole assumes with a wink and nod that the hacker acted in good faith. In return, it will give them $10 million for pointing out a vulnerability. But it wants its quarter-billion back.

Wormhole has not yet responded to a Decrypt request for comment.

In addition to connecting Ethereum and Solana, Wormhole also works with Avalanche, Binance Smart Chain, Oasis, Polygon, and Terra. It allows users of one chain to take "wrapped" assets and use them on another chain, often so they can take advantage of lower fees or different applications across networks.

But to get their Ethereum into Solana, they must first lock it into a smart contract and then get an equivalent amount in Wrapped Ethereum. They can then trade WETH for Solana-based tokens. If the message above is accurate, the hacker was able to short-circuit this and mint WETH without keeping ETH locked up.

Editor's Note: This article has been updated to include Wormhole's confirmation of the exploit as well as the revised figure of $320 million.

Corneliu Boghian thanks for sharing
February 3, 2022 at 6:53pm
Andries Van Tonder thank you Adonel.
February 3, 2022 at 6:03pm