In Latest Crypto Hack, 20M Tokens Lost as Market Maker Wintermute Takes Blame

Attacker deployed layer-1 multi-signature technology to the layer-2 before the Wintermute recovery team


Source: Optimism


key takeaways

  • A hacker has acquired 20 million Optimism governance tokens intended for a loan
  • The attacker has since transferred or sold about one million tokens — but that’s likely just the start

The airdrop of first-time governance tokens from Ethereum scaling solution Optimism has gone awry in a major way — thanks to a third-party the collective tapped to provide liquidity.

All told, about 20 million Optimism governance tokens (OP) that were loaned to facilitate transactions were lost, with cryptocurrency market maker Wintermute taking responsibility for the lapse.

The loan was initially deployed on Wintermute’s wallets on Optimism, but Wintermute CEO Evgeny Gaevoy said in a statement that “we made a serious error.” 

Here’s what happened: The wallet address Wintermute used to receive the loan was inaccessible, because it relied on Ethereum layer-1 multi-signature technology that had yet to be deployed to Optimism, which runs as a layer-2. A layer-1 is the foundational function of a given blockchain, while layer-2s are built on top, typically to provide new features or liquidity.

A hacker, meanwhile, took advantage of the technological lapse to transfer the 20 million OP tokens from layer-1 to layer-2, even as Wintermute scrambled to recover the in-limbo funds. The attacker, however, had as of publication only liquidated about a million of the stolen tokens. 

Loading Tweet..

“L1 is confusing enough for most people to navigate, and L2 brings a new set of paradigms over key management and safety, even for experienced crypto users and teams,” Gaevoy said. 

“We are not sure why they chose not to liquidate all of it at once,” Gaevoy said. “There is hope that it is a white hat exploit, in which case the remaining funds are potentially recoverable. However we are currently operating under the premise that it is not the case, since we haven’t received any communication from them and our message on the chain was left unanswered.”

The attacker still owns 19 million OP tokens. Wintermute said the company plans to buy back the tokens once the attacker sells, saying the purchase “can potentially create price volatility in the token,” but that the market maker will “make best efforts to smoothen the effect.”

The Optimism Foundation has not chosen to update its network — likely requiring a hard fork — to halt the movement of stolen OP tokens that have not yet been stolen or sold as the foundation believes that “using centralized control to attempt a partial recovery would set a significant precedent.”

Security flaws and the illicit process of attaining cryptoassets have become a common problem for many platforms, and lawmakers are eager to look for solutions.

It comes down to the hallmark phrase, “Not your keys, not your coins,” Ashton Wolfe, the project lead of Crypto Fight Club, told Blockworks.

“Of course, to protect people’s assets, governments will think that continuously hammering down on regulations will fix this solution,” Wolfe said. “Unfortunately, this still hasn’t worked, because it is a very slow process, and users resent uploading private documents to these counter-parties in order to use the platform.”

Don’t miss the next big story – join our free daily newsletter.


Upcoming Events

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

ao cover.jpg


Arweave recently launched the testnet for AO computer, a new messaging protocol that will sit atop a PoS network and aims to become a scalable global compute platform through parallel processing and modularity.


The “fastest-growing ETF in history” has seen net inflows on every trading day since its Jan. 11 launch


Relm and Chainproof will provide insurance quotes to distributed validators


DLC.Link uses a Taproot-based Bitcoin multisig to let institutions mint dlcBTC, starting on Arbitrum


Pre-seed Bitcoin startup deals rose 360% in 2023, a TVP report shows


Circle’s new smart contract to allow holders of BlackRock USD Institutional Digital Liquidity Fund to redeem shares for its stablecoin


Uniswap says it was not surprised to receive a Wells notice given the SEC’s “abusive” use of power as of late