Bridge Update
The unauthorized wrapped ALPH held in the attacker's wallet was burned yesterday. 500,000 unbacked wrapped ALPH had already been sold on Uniswap prior to the burn. Alephium will supply the native ALPH required to back these tokens.
For users affected by the drained bridge assets, we remain committed to making them whole and are working on the best path forward.
Following the burn, the most likely path forward is now a relaunch of bridge operations. We currently believe this is the fastest, safest, and simplest solution. Once the bridge is safely restored, users would be able to redeem through the bridge as originally intended. A separate redemption process for wALPH holders remains a fallback option if needed.
The vulnerability has been fixed. We're conducting extensive review and security assessments before any relaunch, as we prioritize security over speed.
This is our most likely path, though it may evolve as reviews progress.
Full postmortem and further updates to follow.
Powfi Update 💥
Following very positive discussions with several partners, the Powfi codebase has been upgraded to support direct integrations with our $ALPH Staking Layer through a referral-based framework.
How it works:
Traditional B2C Workflow
▪️ A user holds ALPH
▪️ Connects their wallet to Powfi
▪️ Stakes their ALPH
▪️ User starts earning rewards
New B2B2C Partner Workflow
▪️ An integration partner offers ALPH staking to its users
▪️ The yield offered is the same as staking natively on Powfi
▪️ Staking is attributed to the partner via an on-chain referral tag
▪️ ALPH is staked via the Powfi Staking Layer
▪️ The partner earns a commission
One example from our recent discussions is a mining pool offering ALPH Staking to its users.
Other potential integration partners include: wallets, centralized exchanges, and of course dApps.
This is how the Powfi staking layer scales and maximizes locked circulating supply, strengthening $ALPH and the broader ecosystem.
We'll share more updates as these conversations progress and integrations begin to materialize.
Just another day here at Alephium 👀
Seriously though, there is so much happening, both in response to the exploit and with building Powfi.
Team working at hyperspeed
Bridge Update
Today, we continued work across multiple recovery and investigation tracks.
▪️As part of the bridge incident remediation, the bridge guardians, with support from our security partners, executed an authorized recovery procedure to invalidate the unbacked wrapped ALPH held in the attacker's wallet. This action applied exclusively to unauthorized wrapped ALPH created through the exploit and held by the attacker. It did not affect native ALPH, legitimately backed wrapped ALPH held by users, or addresses that unknowingly acquired unbacked wrapped ALPH through trading activity following the exploit. It also did not affect the Alephium L1 consensus rules. Removing these exploit-created assets from the attacker's control is an important step in the ongoing recovery and remediation process.
▪️ We are advancing the recovery path for legitimate wrapped ALPH holders and have identified all eligible holders via snapshot.
▪️We are confirming the addresses of liquidity providers affected by the exploit, including LPs currently providing liquidity on Uniswap and PancakeSwap, as well as addresses that unknowingly traded against the attacker's transactions.
▪️We have submitted an incident report to Switzerland's National Cyber Security Centre (NCSC) and are coordinating with the relevant law enforcement authorities.
▪️We continue to work closely with @Blockaid_, @SEAL_911, and other investigation partners to trace assets and assess possible recovery opportunities.
▪️In parallel, work continues on the bridge recovery plan, technical remediation, legal and criminal investigation efforts, and the preparation of the full postmortem.
▪️Below, we have published a comprehensive on-chain analysis covering the exploit timeline, affected transactions, fund movements, and the current location of the drained assets.
Read the on-chain report here: https://t.co/dm4xGqhO6K
We will share further updates as the situation develops.
💖 Support RalphStudio!
Keep our RPCs, APIs, and dev tools running for the @alephium ecosystem. Every contribution helps us build better infrastructure.
Support: https://t.co/BtofhYgKb4
RalphStudio has a new home.
Homepage: https://t.co/BD7qmFAPsV
IDE: https://t.co/uSh159FmI6
Developer Portal: https://t.co/6V0mvH9RfX
While the IDE remains available, our primary focus is now developer infrastructure for the @alephium ecosystem.
More to come.
Bridge Update
Over the past 48 hours, the team has been working around the clock on recovery, remediation, investigation, and the future of the bridge.
With regards to legitimate wALPH and corresponding native ALPH: the exact technical implementation for recovery of funds is still being evaluated and depends on several factors. Regardless of the implementation chosen, the objective remains the same: legitimate holders will be able to recover their ALPH, while assets illegitimately created through the exploit will not benefit from the recovery process.
We continue to work with security and investigation partners to trace the drained assets and assess possible recovery opportunities and we are grateful for their ongoing support.
At the same time, we are initiating coordination with legal counsel, relevant authorities, and law enforcement regarding the incident.
Further updates will be shared throughout the week as work progresses.
I used to work with one of their core dev in a fintech startup and we worked on getting pcidss certified together. So i would say alephium’s infra sec work is better than 90% of DeFi project out there.
Important Reminder 🚨
There are accounts impersonating Alephium, our team, and our moderators across all social media channels.
We do NOT have a ticket system or support team.
Do not share your private keys with anyone, and do not click links from unverified sources.
Please verify account names carefully before engaging.
We will never DM you first, and all official updates will come from verified Alephium channels only.
Thank you.
Alephium Team.
The lows people will sink to.
Please be aware that fake pages such as this are doing the rounds, trying to capitalise on our situation.
Be VERY alert. Double-check EVERYTHING.
@alephium is the only account for official comms regarding the bridge exploit.
💬 Onchain Message:
To the individual responsible for the Alephium bridge exploit:
We are prepared to treat this incident as a white hat disclosure under the following terms:
1. Return 90% of the drained assets to:
0x238640C0F74A95485e986Fa26D434fF7B216D058
within 72 hours of this message.
2. You may retain 10% of the returned assets as a white hat bounty.
Upon receipt of the 90%, Alephium will consider the matter resolved and will publicly acknowledge your cooperation.
Contact [email protected] with a message signed by one of the addresses involved in the exploit for further communication.
We would prefer to resolve this matter quickly and cooperatively for the benefit of affected users.
Alephium Team
https://t.co/neFjYBp0uQ
A sincere thank you to the @blockaid_ team for being the first to detect the exploit and for their support throughout the investigation.
We would also like to thank the @SEAL_911 team for their assistance and responsiveness during the incident.
The collaboration and professionalism shown by both teams have been invaluable as we work through this situation.
Update on the Alephium Bridge Exploit
The bridge was shut down shortly after the exploit was identified. No new bridge transactions can be initiated, and the exploit can no longer be executed.
Please withdraw your liquidity and do not swap from ALPH pools on Uniswap or PancakeSwap until further notice.
Confirmed impacts of the exploit:
1. Assets illegitimately drained from the bridge
The assets confirmed to have been drained are:
Ethereum
• 200,967 USDT
• 17,594 USDC
• 5.18 WETH
• 0.335 WBTC
BNB Chain
• 36,750 USDT
• 24.386 WBNB
The affected assets included both user funds and assets belonging to Alephium.
We are currently exploring all available options to compensate affected users. Our objective is to make affected users whole, and we are committed to working toward that outcome. We recognize that this process may take time, but supporting affected users remains a priority for the team.
2. Minting of approximately 13.7 million wrapped ALPH on Ethereum
However, ALPH held within the bridge was not drained.
Users whose ALPH remained locked in the bridge at the time of the shutdown will be able to recover their funds. We will provide a dedicated recovery process allowing affected users to reclaim their ALPH.
Because the bridge has been shut down, the attacker cannot redeem or bridge these wrapped ALPH back through the Alephium bridge. We therefore ask users not to provide liquidity to ALPH pools on Ethereum or BNB Chain, to withdraw any existing liquidity, and not to swap against these pools. Additional liquidity or trading activity would increase the attacker’s ability to realize value from the unauthorized wrapped ALPH.