In Latest Crypto Hack, 20M Tokens Lost as Market Maker Wintermute Takes Blame

Attacker deployed layer-1 multi-signature technology to the layer-2 before the Wintermute recovery team

article-image

Source: Optimism

share

key takeaways

  • A hacker has acquired 20 million Optimism governance tokens intended for a loan
  • The attacker has since transferred or sold about one million tokens — but that’s likely just the start

The airdrop of first-time governance tokens from Ethereum scaling solution Optimism has gone awry in a major way — thanks to a third-party the collective tapped to provide liquidity.

All told, about 20 million Optimism governance tokens (OP) that were loaned to facilitate transactions were lost, with cryptocurrency market maker Wintermute taking responsibility for the lapse.

The loan was initially deployed on Wintermute’s wallets on Optimism, but Wintermute CEO Evgeny Gaevoy said in a statement that “we made a serious error.” 

Here’s what happened: The wallet address Wintermute used to receive the loan was inaccessible, because it relied on Ethereum layer-1 multi-signature technology that had yet to be deployed to Optimism, which runs as a layer-2. A layer-1 is the foundational function of a given blockchain, while layer-2s are built on top, typically to provide new features or liquidity.

A hacker, meanwhile, took advantage of the technological lapse to transfer the 20 million OP tokens from layer-1 to layer-2, even as Wintermute scrambled to recover the in-limbo funds. The attacker, however, had as of publication only liquidated about a million of the stolen tokens. 

Loading Tweet..

“L1 is confusing enough for most people to navigate, and L2 brings a new set of paradigms over key management and safety, even for experienced crypto users and teams,” Gaevoy said. 

“We are not sure why they chose not to liquidate all of it at once,” Gaevoy said. “There is hope that it is a white hat exploit, in which case the remaining funds are potentially recoverable. However we are currently operating under the premise that it is not the case, since we haven’t received any communication from them and our message on the chain was left unanswered.”

The attacker still owns 19 million OP tokens. Wintermute said the company plans to buy back the tokens once the attacker sells, saying the purchase “can potentially create price volatility in the token,” but that the market maker will “make best efforts to smoothen the effect.”

The Optimism Foundation has not chosen to update its network — likely requiring a hard fork — to halt the movement of stolen OP tokens that have not yet been stolen or sold as the foundation believes that “using centralized control to attempt a partial recovery would set a significant precedent.”

Security flaws and the illicit process of attaining cryptoassets have become a common problem for many platforms, and lawmakers are eager to look for solutions.

It comes down to the hallmark phrase, “Not your keys, not your coins,” Ashton Wolfe, the project lead of Crypto Fight Club, told Blockworks.

“Of course, to protect people’s assets, governments will think that continuously hammering down on regulations will fix this solution,” Wolfe said. “Unfortunately, this still hasn’t worked, because it is a very slow process, and users resent uploading private documents to these counter-parties in order to use the platform.”


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Tags

Upcoming Events

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

Screen Shot 2024-04-22 at 11.51.05.png

Research

The Jito Network is MEV-aware infrastructure that strengthens the performance, decentralization, and security of Solana. As the chain matures, Jito and all of its market-leading products are poised to play a vital role.

article-image

The world’s largest asset manager sees BTC fund outflows for the first time, while the most money left Fidelity’s product

article-image

Binius operates over binary code and is designed to store information using bits

article-image

The Fed once again opted to not surprise markets on Wednesday, moving to hold interest rates

article-image

Celebrity crypto ads should only exist if they do something really creative or really silly — Eminem’s ad did neither

article-image

The profits were driven by interest earned on US Treasury holdings, as well as market gains on bitcoin and gold

article-image

The world’s largest asset manager led a $47 million funding round by a blockchain-focused firm it has worked with before