Binance Identifies Suspects Who Stole From KyberSwap Whales

DeFi platform KyberSwap suffered a frontend security breach last week that allowed hackers to steal crypto from two whale wallets

article-image

Source: Shutterstock

share

key takeaways

  • KyberSwap has offered a 15% bounty to its hackers if the stolen funds are returned
  • Binance previously helped recover funds stolen from Curve Finance and Axie Infinity

Binance may have helped crack last week’s $265,000 hack on decentralized exchange (DEX) platform KyberSwap.

Binance CEO Changpeng Zhao said on Saturday that his exchange’s security team identified two suspects behind the attack, and that their identities have been forwarded to the KyberSwap team. 

On Sept. 1, KyberSwap issued an alert to notify users that a hacker exploited a frontend vulnerability which led to the draining of two whale wallets on Ethereum and Polygon. 

The team discovered malicious code in its Google Tag Manager (GTM) which led to fraudulent transaction approvals, which allowed a hacker to transfer user funds to their account. The GTM was then disabled, according to a blog.

“The script had been discreetly injected and specifically targeting whale wallets with large amounts,” KyberSwap said.

The DeFi platform, which doubles as both a DEX and a liquidity protocol, offered a 15% bounty (around $40,000) to the hacker if they returned the funds and spoke with the team. Compromised addresses would be fully compensated, the network said.

Loading Tweet..

Around the same time as the KyberSwap incident, privacy-focused startup ShadowFi also suffered a cyberattack leading to around $301,000 in losses. PeckShield identified the hacker as NeorderDAO, a little-known crypto collective whose website is now offline.

Binance has often shown commitment to helping out crypto projects. Last month, the exchange managed to recover a majority of the funds hackers stole from DeFi protocol Curve Finance. It also helped Axie Infinity recover nearly $6 million allegedly stolen by North Korean hacking unit Lazarus Group in April. 

DeFi hacks have been exploding in the past two years, hitting over $1.2 billion in the first quarter of this year alone, according to Immunefi. The Federal Bureau of Investigation recently warned against such exploits, saying cyber criminals are on the lookout to abuse the complexity of cross-chain functionality. 

Kyber’s KNC token has fallen 5% since the hack to $1.65, data from TradingView shows.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Tags

Upcoming Events

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

Avail.jpg

Research

Data publishing costs have historically been a bottleneck for rollups, and as more rollups launch, interoperability will continue to be a major challenge. Avail presents a potential solution to rollup fragmentation through its three products: Avail DA, Nexus, and Fusion, which together aim to unify the web3 experience.

article-image

The Bitcoin halving is a spectacle that only comes round once every four years

article-image

The SEC alleges that Justin Sun spent nearly 400 days in the US from 2017 to 2019

article-image

Short-term “sell the news” reactions could follow new BTC price peaks months from now, industry watchers say — but only if history repeats itself

article-image

While crypto fundraising remains well off its bull market highs, Q1 data shows capital is returning to the space

article-image

Billed as a better BRC-20 fungible token standard, Bitcoin Runes launches tomorrow

article-image

Bitcoin miners need to explore unconventional energy avenues or be buried by the financial realities created by this halving