@BlockchainFXcom Tell us how will we be able to claim after you recycled the domain multiple times because of the scam warnings from our dex wallets with the previous domains?
If you were holding $H on Binance Alpha, Bybit, Bitget, KuCoin, MEXC, or Gate during the snapshot, here's how the new H airdrop will work on each exchange 👇
The full Quantstamp report is now available to read on our website: https://t.co/AoWdPC6ZJy
Transparency matters to us, and you deserve nothing less. Recovery plan and next steps to follow.
While we work on a recovery plan for everyone affected, we want you to see exactly what we see.
We’ve set up a live tracker of the exploiter’s addresses and downstream transfers so our community can follow the situation in real time: https://t.co/FlOp4TUPfm
This page has been shared with all CEXes/DEXes/Aggregators and will be continuously updated.
We are also offering a 1M $USDT bounty for any information leading to recovery and all recovered funds will be used for the buy back of $H.
Please contact [email protected] if you have any information.
We committed to keeping the community informed.
Our complete post-mortem on the June 8 $H incident is live. A recovery plan is underway for those affected. Stay tuned.
https://t.co/jtyWDtiCR4
We're aware of a security incident involving the compromise of private keys belonging to a member of the Humanity Foundation. The safety of our community is our top priority, and we want to be fully transparent about what we know.
As a precaution, please do NOT interact with the bridge or any liquidity pools until we give the all clear. This is the single most important step you can take to protect your funds right now. We are actively working with leading security experts and our exchange partners to assess the scope of the incident and secure all affected systems.
We're deeply sorry that this has happened. Protecting this community is our responsibility, and we don't take that lightly. We will share verified updates as soon as we have them and we won't speculate before facts are confirmed.
Official updates will only come from this account or @terencekwok
Beware of the scammers and impersonators who exploit moments like this. We will never DM you first or ask for your seed phrase or private keys.
INCIDENT UPDATE:
Last night, June 8, the H token was hit by a coordinated attack across Ethereum and BSC. While we’re still investigating this incident, we want to be transparent with our community about what happened.
As of right now, ~$36M+ has been stolen across both chains and dumped. This was a result of a breach that happened after an employee’s laptop was compromised.
Three of six Gnosis Safe owner keys controlling the Hyperlane bridge ProxyAdmin were compromised. The attacker used these to transfer ProxyAdmin ownership to their own wallet, then upgraded the bridge contract to a malicious implementation and swept ~141.2M H in a single transaction.
Three of five BSC Safe owner keys were also compromised. The attacker performed the same ProxyAdmin seizure on BSC, deployed a malicious implementation with an unlimited mint function, and minted 200,000,005 H in two tranches directly to their wallet.
We’ve now halted all deposits and withdrawals to the affected bridges and are working with all related parties, including exchanges, to minimize the damage. Further to our internal investigation, we’re also working closely with the police to investigate this incident and recover some of the stolen funds.
People in this community worked hard for what they hold here, and we feel the weight of that. We want to apologize for what has happened and thank you for your patience, messages, and for sticking with us.
We know words can't fix this but we're going to show up, keep you in the loop, and do the work to earn back the trust you placed in us. We're not going anywhere and are still continuing to build.
We’ll be publishing a detailed post-mortem soon.