@WX228866862@RichardHeartWin Yeah that was a scammer impersonating the Verus devs. There is no way to 'file your claim' in any official Verus channels, whether that be on Telegram or Discord, and that is a method that scammers use. This is made very clear in the official Verus groups on both platforms
@WX228866862@RichardHeartWin There isn't a channel in the official Verus discord or telegram groups called 'Dev Team Announcement' so that sounds like a scammer impersonating the devs. Could you send a link to this group? The words that you said these people used sounds a lot like the words that scammers use
@KarmaCpu There is no company behind Verus to 'fire' anyone. Everyone who works on Verus are volunteers as we are a community project. I really don't know why people think this is an 'inside job' as there is zero evidence to back that up
@Cedric_Crispin@RedPandaMining I don't know the full technical reason, but I believe it is more of a safety measure to prevent further damage. You'd have to speak to someone with better technical knowledge of Verus for the full explanation but there's also a description in the post-mortem on @VerusCoin
UPDATE: The Verus bridge exploiter returns 4,052 $ETH (~$8.5M), 75% of stolen funds, after accepting a negotiated settlement, retaining 1,350 $ETH (~$2.8M) as a bounty in exchange for no legal action.
@KarmaCpu@RedPandaMining That 'hackathon' was run entirely by a community member, and the 'prize' amount was chosen entirely by them from their own money. The rest of the Verus community, or the devs, had no say in that. Also, the Verus ID vault wasn't cracked during that test so idk how that is relevant
@Cedric_Crispin@RedPandaMining Mining was frozen as the attacker used an invalid transaction as part of the attack, which miners/the daemon recognised and halted mining to prevent further harm to the chain
@0xDestinyae@F0rkedNft@0x15_eth@VerusCoin@immunefi@sherlockdefi@PashovAuditGrp It's something that will be discussed heavily in our community as part of the recovery. We're in a worse position than VC or ICO-funded projects to be able to fund a bug bounty programme, but it's something that is obviously important and something that is clearly needed
@0xDestinyae@F0rkedNft@0x15_eth@VerusCoin We would reward responsibly-disclosed security vulnerabilities (and would've rewarded this exploit if the attacker had disclosed responsibly rather than exploiting, as proven by the fact that we offered the bounty). We just don't have a full programme on something like ImmuneFi
JUST IN: The Verus Bridge exploiter has returned 4,052 $ETH ($8.5M) after draining $11.58M from the protocol.
The returned funds represent 75% of the stolen assets, leaving 25%, or 1,350 $ETH ($2.8M), as a bounty, per PeckShield.
#PeckShieldAlert The @veruscoin Bridge exploiter has returned 4,052.4 $ETH (~$8.5M) to the team address: 0xF9AB...C1A74.
The returned funds represent 75% of the stolen total, leaving a 25% bounty (1,350 $ETH, ~$2.8M) in the exploiter's wallet.
Prayers answered 🙏
The requested amount, within the deadline set by the Verus community, has been returned. The way this community came together in such a moment is extraordinary. We have remarkable and wonderful people from all over the world. $VRSC
https://t.co/Dzj8O8WIYy
@clownbagz@VerusCoin Tf do you mean no? Also funny you call yourself a kol (whether that be ironic or not) when your following list is like 4x longer than your followers list..
To the Verus<->Ethereum Bridge Exploiter:
Members of the Verus community and its developers have discussed a set of terms, detailing the size of the bounty, obligations from your side and ours, and how the funds can be returned.
1. We have agreed that the bounty amount will be 1350 ETH. If you adhere to these terms, we will consider these 1350 ETH a reward for your exposing of a vulnerability, and we would publicly request to all interested parties that the 1350 ETH be considered your legitimate bounty.
2. If the funds are returned to the address 0xF9AB28cB7b72B518e6a351FbdaBe69362cBC1A74, minus 1350 ETH, meaning a total return of 4052.4 ETH within 24 hours after this post, Verus community members and developers, and everyone we currently know to be involved in investigating the event, will halt any existing investigations into you to the best of our ability, and we will not press charges or pursue extralegal consequences. We will consider the address that holds 1350, either as change or if still in the source as the bounty address.
If you return a total of 4052.4 ETH to the address 0xF9AB28cB7b72B518e6a351FbdaBe69362cBC1A74 within the 24 hours specified above, we will understand that as your agreement to these terms, and we will uphold our stated agreement to cease further investigation into you, not initiate new investigation of you, not press charges, and not seek additional consequences. We will also post a public acknowledgement, referencing the 1350 ETH and publicly state that we consider those funds to be your bounty. If further communication is required to come to an agreement, please refer to the following contact points, as mentioned in previous messages:
email: [email protected]
z-address on Verus (for encrypted memo communication): zs1wl6e6qe8z8n8t8jp4qxek5ey53t9xajzwxc75gj72wrcwuq6ha4mdg0v8p6z8wpkz2fhxrqlayc
For confirmation that this offer is coming from the Verus Community, you can see the same message posted on the Verus Discord, in the announcements channel.
@Core3io@VerusCoin Oh, also I saw your website and noticed that you have lots of crosses for things on Verus that actually are there. Things like whitepaper missing (it's at https://t.co/5do9gkEGCW), team transparency being private, etc. I'm more than happy to go through some of this and correct it