Connect with us

À la une

Raydium exposed, hackers load up on $2 million in cryptocurrency

Published

on

Raydium, the decentralized cryptocurrency exchange protocol, fell victim to hackers this time.

A flaw in the DEX code allowed a malicious user to to hijack administrator credentials.That allowed him to access the platform and empty it.

According to the first impressions of the research team, the vulnerability detected in Raydium is related to a programmatic function in the platform code.. This would be designed to accurately make withdrawals from the exchange.

Analysts from the security firm Ottersec also found other clues as to how the attacker managed to gain access to the administrator account.

Ottersec is composed of independent consultants and specializes in web3 security. In addition to Raydium, the company frequently performs audits for clients such as PancakeSwap, Argo, and other well-known names in the cryptocurrency sphere.

Advertisement

Around 2 p.m. UTC time on the 16th of this month, Raydium’s transaction log showed a number of transactions made by the administrator account.

Several signs rang alarm bells. First, transactions, which numbered nearly a thousand, were all withdrawals of funds.. Second, the withdrawals were made within seconds of each other.

Evening attack

What’s worse, and a sign that this was a hack, is. transactions were not supported by the corresponding deposit of funds in LP tokens.. It is therefore theft.

By exploiting the vulnerability in Raydium, the cybercriminal was able to extract just over $2 million. Among the tokens mined are USD Coin (USDC), Wrapped SOLTether (USDT) and, of course, Raydium (RAY).

On Twitter, observers associated with the Prism DEX were the first to issue a hacking alert on the Raydium platform. “Someone is taking tokens from Raydium without depositing LPs. REMOVE your PRISM/USDC tokens immediately,” they wrote on their account.

A lire aussi :   Man loses $2M in cryptocurrency dating app scam

Moments later, Raydium officials acknowledged that the exchange had been hacked.

So far, the exchange has not ruled on the replacement of funds to affected users. Logic assumes that this will be the short-term course of action while the matter remains under investigation.

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.