x
Black Bar Banner 1
x

Alert!  New Secured Wallets are installed! new Blog system with AI  power and auto blog curation coming soon  Alert! 

Ads by Markethive - View All
Blogs
The Blog Feed
Write a New Blog Post
Search Blog Status
Most Viewed
Most Recent
Most Shared
Alphabetical
Blog Main Menu
Markethive Blog (default)
All Blogs
My Blog Posts
Friends' Blogs
Blog Categories
All
Advertising
Blockchain & Cryptocurrency
Business Development
Diet & Weight Loss
Environmental
Health and Wellness
History and Culture
Home and Garden
Marketing
Mentoring & Training
Money & Finance
Other
Political
Prayer & Religion
Programming & Technical
Real Estate
Search Engine Optimization
Social Media
Spirituality
Sports & Recreation
Transport
Travel & Events
Website Design
Blogging Tools & Assets
My Blog Info
Members Subscribed to You
Blogs You Are Subscribed To
Website Widget
Wordpress Plugin

SushiSwap's Token Launchpad Hacked for Over $3M in Ethereum

Posted by Andries Van Tonder on September 17, 2021 - 10:13am Edited 9/17 at 10:15am


SushiSwap’s Token Launchpad Hacked for Over $3M in Ethereum

An NFT auction on the SushiSwap token launchpad has been reportedly hacked for more than $3 million worth of Ethereum.

By Andrew Asmakov

SushiSwap’s token platform called MISO was reportedly attacked on Thursday, with the hacker stealing 864.8 Ethereum, approximately $3 million in current prices.

SushiSwap is one of the largest decentralized exchanges (DEX) in the world and rival to Uniswap, with more than $495 million in trading volume over the last 24 hours, per CoinGecko.

As described on the project’s website, MISO is “a suite of open-source smart contracts created to ease the process of launching a new project on the SushiSwap exchange.”

According to SushiSwap’s CTO Joseph Delong, MISO fell victim to a so-called supply chain attack, which saw an anonymous contractor going under the GitHub handle AristoK3 inject malicious code into the platform’s front end and replace the auction’s wallet with their own address.

The exploited NFT auction in question is automobile-themed Jay Pegs Auto Mart, which has already been patched.

According to Ethereum blockchain explorer Etherscan, which has identified the address shared by Delong as the one involved in the MISO exploit, the attack occurred at 12:04 pm Eastern time on Thursday.

This is not the first time MISO has encountered a similar problem. On a previous occasion, however, the platform’s team got away lightly.

Last month, samczsun, a security researcher for venture capital firm Paradigm, discovered a vulnerability while examining the smart contract code of the BitDAO token sale on the MISO platform.

The researcher said that the vulnerability could have potentially resulted in a loss of about $350 million.

The sale concluded without any incident, raising $365 million in the process. However, it required the BitDAO team to manually end the token auction to neutralize the potential threat.

Hacker’s identity known?

SushiSwap claims there are reasons to believe that the hacker is a Twitter user @eratos1122, who “has done work with Yearn.Finance and approached many other projects.”

However, the Twitter profile Delong linked to shows a different GitHub handle, not AristoK3 as SushiSwap claims.

Delong added that SushiSwap asked crypto exchanges FTX and Binance to share the attacker’s hacker’s know-your-customer (KYC) information, “but they have resisted on this time-sensitive matter.”

“I recommend that you test your own user interface in order to identify exploits early on,” said Delong.

He also stated that SushiSwap instructed the company’s lawyer Stephen Palley to file a complaint with the FBI if the stolen funds are not returned by 8 am Eastern Time on Friday.

Andries Van Tonder yes, it doesn't stop Bill
September 17, 2021 at 3:10pm
Bill Rippel WOW!! Not another one. Something has to be done with these hackers.
September 17, 2021 at 3:04pm