@LidoFinance Frontrunner returned their share: https://t.co/Nz8vpndJv5
When can I expect to hear from you @LidoFinance?
Will even let you keep a 10% bounty π₯³
Hi there @LidoFinance, it's me again. Was just hacked for 20 Eth, almost all of which got funneled to you.
https://t.co/no0gmN0DLC
Any chance you want to return those dirty, dirty funds?
Found the original attacker (too dumb to successfully pull it off): https://t.co/XPuzSJho3i
Traced through TC to 0xC8fB3af887C79D8D701334F8CB02b918a8eD139d
who had weeks earlier sent me this message:
Guess I should've responded π€·ββοΈ
@cryptoQuoc A contract upgrade is not equivalent to a chain fork. If you truly want to offer non-custodial ownership, make your contracts immutable.
Until then, you don't get to hide behind decentralization, code is law, or whatever other excuse you prefer to avoid returning stolen funds.
Should note that @CoWSwap is fine; just like last time, seems to be a bad solver contract which lets others take cowswap's fees.
Solver will be on the hook for losses, not users.
Ever seen an MEV bot hacked by a private bait tx?
0x9e5 backruns bloxroute's private order flow, splitting any profits between bloxroute, the user, and themselves.
Typically the user refund is a simple internal transfer to an EOA. In this case however ...
The user specifies a contract, which reenters the MEV bot and asks for all of its weth.
The MEV bot won't send an unprofitable tx, so the hacker has to send an additional bundle to activate the theft. Note the small bribe paid here which helps ensure the correct tx ordering.
@stakefish New alpha for blackhat hackers unlocked!
Just send the funds to a contract which disperses them among several addresses.
You too can become a non-custodial service which sadly can't return any stolen funds!
Bruh, the funds are in your upgradeable smart contract, @stakefish You can return them, you just don't want to.
Would love to see this litigated somewhere, like when Oasis was forced to rug the Jump hacker.
Crypto lawyers how/where can we make this happen?
You're a blackhat with the keys for a compromised withdrawal address.
288 Eth suddenly become available. What do you do?
If you're this knucklehead, you immediately send out a mempool tx with a 206 Eth gas fee, then, when challenged, say screw it, and dump the entire stack.
Hi @LidoFinance , it's me again. Some more stolen funds headed your way. Would be amazing if you could return them, just like you did here: https://t.co/6rUpBLJBRb
https://t.co/i0kxjFMVdV
Hi @LidoFinance , sorry (not sorry) we couldn't pay you as much as @stakefish , but would really appreciate it if you can return the stolen funds as well.
https://t.co/vHkIBv9VCT
Hi @stakefish , I'm helping whitehat a compromised withdrawal address.
Unfortunately, it seems that if the bad guys can't have it, nobody can π’
Any chance you can return those stolen funds to the rightful owner?
https://t.co/4TPQ4U6vuG
Hi @krakenfx@krakensupport , the lunatics with the stolen private key forced me to dump 92 Eth to your validator.
Please reach out to return the stolen funds.
https://t.co/ztz4l1fTFg
Hi @stakefish , I'm helping whitehat a compromised withdrawal address.
Unfortunately, it seems that if the bad guys can't have it, nobody can π’
Any chance you can return those stolen funds to the rightful owner?
https://t.co/4TPQ4U6vuG