CoW Swap hacker milks over 550 BNB using ‘solver’ exploit

Share This Post

Security firm PeckShield reported that the hacker successfully drained roughly 551 BNB off CoW Swap into Tornado Cash, which was worth around $181,600 at the time of writing.

Decentralized exchange (DEX) protocol CoW Swap recently suffered an attack, losing at least 550 BNB (BNB) in a contract exploit that approved fund transfers from the protocol.

Blockchain surveyor MevRefund flagged the event and detected that the funds seemed to be moving away from CoW Swap. The MEV searcher warned the DEX and its users of the exploit in a Twitter thread.

According to the Smart contract auditing firm BlockSec, a wallet address was added as a “solver” of CoW Swap by a multisig. Then, the address invoked the transaction to approve DAI (DAI) to SwapGuard, which then led to SwapGuard transferring DAI from the CoW Swap settlement contract to other addresses. 

Blockchain security firm PeckShield estimated that around 551 BNB was lost, worth $181,600 at the time of writing. After stealing the assets, the hacker moved the funds to the infamous crypto mixer Tornado Cash.

Flowchart showing movement of stolen funds from CoW Swap. Source: PeckShield

During the attack, some members of the community panicked and urged users to revoke approvals from the DEX. However, the decentralized finance (DeFi) protocol said that this isn’t necessary.

According to CoW Swap, the settlement contract which was exploited only has access to the fees that the protocol collected in a week. The team said that it is unable to directly access user funds without an order signed by users. 

CoW Swap has not yet responded to Cointelegraph’s request for comment.

Related: Scam alert: MetaMask warns crypto users about address poisoning

Meanwhile, despite the hacks that surround DeFi, the space has had a prolific start in 2023 according to a report from DappRadar. Data showed that protocols saw significant growth in their total value locked in the month of January.

In other news, the United Nations also reported that North Korean hackers have stolen more crypto in 2022 compared to other years. The report estimates that hackers linked to North Korea were responsible for around $630 million to $1 billion in stolen crypto assets last year.

Read Entire Article
spot_img

Related Posts

Memecoins Resurgence? POPCAT And MEW Lead The Way With 20% Surge

As the crypto market settles in on this new phase of the crypto cycle, some memecoins have shown remarkable performance over the last couple of days Cat-theme tokens have significantly grown in

$12 Million Crypto Seizure: Dutch Authorities Arrest Suspect Of ZKasino Rug Pull

About two weeks ago, the crypto space faced another alleged rug pull This time, the gambling platform and blockchain casino ZKasino was at the center of the accusations, with many investors claiming

Fantom Revival: Crypto Analyst Predicts A Jump To $1.2 For FTM Price

Fantom (FTM) had initially reclaimed the $1 level back in March and expectations were that the coin would rise to $2 But that was before the market crash sent prices spiraling, and Fantom lost almost

XRP Forms On-Chain Signal That Led To 16% Crash Last Time

On-chain data shows that many old coins have moved on the XRP network recently, a sign that proved to be bearish for the coin last time XRP Age Consumed Metric Has Registered A Large Spike According

Bitcoin Price Surges Towards $61,000, Eyeing Potential Breakout To $67-$68k Range

Bitcoin (BTC), the largest cryptocurrency in the market, has experienced a notable resurgence in its bullish momentum, with the Bitcoin price reclaiming the crucial $61,000 threshold  This recovery

Bitcoin Analyst Says Rally To Over $90,000 Programmed As Money Supply Grows

Bitcoin price action might be dicey, undergoing a major corrective phase However, even as $60,000 looks slippery for upbeat bulls, some analysts are optimistic that the coin is ready for a strong leg
- Advertisement -spot_img