@GovKathyHochul So let me get this straight… As soon as I voluntarily get intoxicated i should instantly not be responsible for my own decisions and have no accountability for those decisions? What dimension are you from? Do they have brain cells there? Maybe you should consider getting some.
@America_Ghost_@hayasaka_aryan I am glad pokemon overprinted and ruined every scalper. They all deserved it for their hostile antics. I am considering getting new pokemon cards to open because of the overprinting. Higher hit rates? More supply? Lower cost? What actual fan of pokemon doesn’t want these things?
@osmosis Pendle has had one of the more elegant solutions to defi tokenomics imo. Especially when it comes to maintaining token incentives for their LPs and limit orders. Might not be a bad idea to check it out for some inspiration. Otherwise 👀🧪
@Loxists@nickycakes@Warcraft How can you flaunt your own virtue signaling and pretend to crusade for “minorities” with clear racist and religious genocidal hate pasted across the front of your profile?
Please google “hypocrite”
@tonyler_ Cosmos Labs attempted and failed to prevent the attacker from accessing the thorchain refund when the Cosmos Hub was restarted. Explain how this is “serious and professional” https://t.co/a3jeMwZOLa
Neutron / Astroport exploit: what happened when the Cosmos Hub restarted.
The 1.2M cosmos:native sweep worked. The 168,990 ATOM THORChain refund didn't get caught. It landed on the attacker a minute after the restart, and he sold all of it for about 100 ETH.
Correction first
In my last post I said the refund couldn't move once it landed, because the Hub had blocked the attacker's address. That turned out to be wrong, it appears the developers of the hub failed to correctly block the attackers address, when they had a ~6 hour window to act.
What worked
The Hub restarted at 10:06 pm AEST on v28.3.0. In the first block (33,086,741), the upgrade moved 1,227,121.37 ATOM off the attacker's address to cosmos1z8pq5cn7tdrwwzlwm0e44fgq07e43ner6vph64. It's still there, untouched. That's about $2.2M kept from him.
What didn't
10:07:38 pm, block 33,086,748. THORChain's vault sent the refund, 168,990.898794 ATOM, to the attacker's address.
10:09:29 pm, block 33,086,761. He signed a 500,000 ATOM IBC transfer to Osmosis. It was included in a block, he paid the fee, and his account sequence went from 8 to 9. It failed only because he asked for more than he had.
That transaction should never have reached a block if the address block was working.
3:54:58 am, block 33,090,325. He tried again with the right amount. It went through.
Where it went
He sold it on Osmosis in chunks of about 20,000 ATOM between 3:58 and 4:48 am, for 266,841 USDC, an average of $1.58.
188,832 USDC went through Noble and Circle's CCTP to 0xe149310eB8b1b3D9C471CcD81819D393621fBA5c and was swapped to $ETH within minutes. +70.84 ETH.
50,000 ATOM went to a new key first. 30,000 of it made a round trip Osmosis → Hub → Terra → Hub → Osmosis. He then sold it and sent 78,010 USDC through Axelar to a new wallet, 0x9bfcca13b4ac907433ac68766e96309ac867f819. 29.22 ETH, never sent.
53 minutes from the Hub to ETH.
Root cause: two gaps
The refund arrived after the sweep. The upgrade moved what was on the address at block 33,086,741. The refund came seven blocks later.
THORChain had GAIA halted (HALTGAIACHAIN = 1), but signing for GAIA was never halted (HALTSIGNINGGAIA = 0). My reading is that the halt stops THORChain watching the Hub, not signing for it. The vault's refund went out as soon as the Hub produced blocks. THORNode still shows the refund as "not signed" because it can't see the Hub.
The ante-handler block didn't reject him. A transaction the ante-handler rejects never reaches execution. His reached the bank module and paid a fee. I can't see the v28.3.0 code (only v28.0.0 is public), so I can't say why. The chain shows it wasn't enforced for his address on an IBC transfer.
Both gaps were visible on-chain by 10:09 pm. The refund sat on his address for 5 hours 47 minutes before he moved it.
Where the attacker's funds are now
0xEF6c5A31df984c8569236a0AbC1f27580E2a5D54: 671.0 ETH
0xe149310eB8b1b3D9C471CcD81819D393621fBA5c: 94.43 ETH 0x9bfcca13b4ac907433ac68766e96309ac867f819: 29.22 ETH
New Cosmos-side addresses from last night: osmo1erq7tre6nk0jfx203z8ey75g4m7yfrckl3qx87 cosmos1erq7tre6nk0jfx203z8ey75g4m7yfrckh2nk3v terra1utez3t0nvg34d9xfswn8058kypney2c3pkx883
Worth taking from this
A sweep in an upgrade handler only covers what's on the address at that block. Anything still in flight needs its own plan.
Test an address block with a real transaction as well as a simulated one, and watch the account sequence right after restart.
Halting a chain in THORChain doesn't stop outbound signing for that chain.
@cosmoshub@THORChain @Osmosis_Zone @Neutron_org@astroport_fi