INCIDENT UPDATE:
Last night, June 8, the H token was hit by a coordinated attack across Ethereum and BSC. While we’re still investigating this incident, we want to be transparent with our community about what happened.
As of right now, ~$36M+ has been stolen across both chains and dumped. This was a result of a breach that happened after an employee’s laptop was compromised.
Three of six Gnosis Safe owner keys controlling the Hyperlane bridge ProxyAdmin were compromised. The attacker used these to transfer ProxyAdmin ownership to their own wallet, then upgraded the bridge contract to a malicious implementation and swept ~141.2M H in a single transaction.
Three of five BSC Safe owner keys were also compromised. The attacker performed the same ProxyAdmin seizure on BSC, deployed a malicious implementation with an unlimited mint function, and minted 200,000,005 H in two tranches directly to their wallet.
We’ve now halted all deposits and withdrawals to the affected bridges and are working with all related parties, including exchanges, to minimize the damage. Further to our internal investigation, we’re also working closely with the police to investigate this incident and recover some of the stolen funds.
People in this community worked hard for what they hold here, and we feel the weight of that. We want to apologize for what has happened and thank you for your patience, messages, and for sticking with us.
@AvalancheFDN This program isnt helping tbh, small projects will remain irrelevant still. Will be more interesting if you could find a better way of supporting new builders.
This week on Avalanche!
Here is some, but not all, of what stood out from our grantees across DeFi, infrastructure, mobility, payments, gaming, and NFTs ⤵️
🔺 @dexalot teased the launch of OmniVaults: one deposit that automatically deploys liquidity across every chain where users are trading, with no extra bridging, no managing multiple pools, and no market makers required. They also shipped a major app upgrade making the platform faster and simpler for traders.
🔺 @WarpGameFDN grew the wheel event prize pool to over $8,000, giving early participants a stronger shot at Enterprise and Pro Nodes plus other rewards on Avalanche.
🔺 @BlackholeDEX recapped a packed year of building exclusively on Avalanche: TWAP and limit orders, in-app cross-chain bridging, zap functionality, and single-click rebalancing. A lot shipped in a short time.
🔺 @BenqiFinance highlighted how tokenized assets on Avalanche can embed rules, incentives, and real utility, deepening DeFi composability across the ecosystem. They also rolled out cross-chain loan repayments from any EVM chain.
🔺 @kardpay reaffirmed two years of building on Avalanche with no plans to slow down, citing the ecosystem's builder support as a key reason for staying long-term.
🔺 @pangolindex put real usage numbers on the board: 69k transactions in 24 hours with active incentive programs across pools.
🔺 @blaze_stream updated Blaze PRIME so selected streams now require subscriptions for Backstage Pass rewards - a move to better support creators and reward the most active community members.
🔺 @AvaxTeam1 hosted the Women Connect event in Manila, engaged 7,000 students at the HUTECH Job Fair in Vietnam, and highlighted @kardpay for powering global event payments with stablecoins on Avalanche.
🔺 @zero________one dropped new independent art collectibles available for collection on their platform.
🔺 @LFG_GTFO kept Gladiator Mayhem Open Beta active with a competitive LFG Stars leaderboard and dropped 10 Forge Keys into the Wheel of Fortune in collaboration with Warp.
🔺 @CodeNekt_Eco opened its L1, described as purpose-built for the mobility industry, to builders, developers, designers, and startups. APIs, SDKs, smart contract support, hackathons, and direct vehicle data integration - all on Avalanche.
🔺 @routescan_io released its Transaction Authorization List tool to simplify tracking authorized transactions on Avalanche.
The builders are building, and it's the community that makes Avalanche worth building on.
There's going to be moments we missed! Let us know ⬇️
Into the @avax BuildGames. SecureClaw goes live in a bit on the great Avalanche🔺
SecureClaw is being positioned to be the top security layer on Avalanche🔺protecting every native user within the $AVAX ecosystem.
Let’s ship 🚢