Harmony’s $100M Hack Was Due to a Compromised Multi-Sig Scheme, Says Analyst

Share This Post

Harmony's $100M Hack Was Due to a Compromised Multi-Sig Scheme, Says Analyst

On June 23, 2022, the Harmony development team announced that $100 million was siphoned from the Horizon bridge, and the organization explained it was working with national authorities and forensic specialists. According to an account published Polygon’s chief information security officer, Mudit Gupta, the Horizon bridge attacker allegedly took control of the multi-signature wallet leveraged in Harmony’s bridge.

Harmony’s Multi-Sig Exploited Polygon’s CSO Says, Harmony Protocol’s Founder Found Evidence That ‘Private Keys Were Compromised’

Three days ago, Harmony explained that it was attacked and the team witnessed $100 million siphoned from the Horizon bridge. “The Harmony team has identified a theft occurring this morning on the Horizon bridge amounting to approx. $100 [million],” Harmony tweeted on Thursday. “We have begun working with national authorities and forensic specialists to identify the culprit and retrieve the stolen funds,” the Harmony team added.

Following the exploit, the very next day, Polygon’s chief information security officer, Mudit Gupta, said that the bridge was a 2 of 5 multi-signature scheme, and anyone with two of the addresses can take control of it. “The hacker compromised 2 addresses and made them drain the money,” Gupta added. Gupta said while the details aren’t public yet he summarized what he believes took place during the hack. “The two addresses were likely hot wallets used to listen for and process legit bridging transactions,” Gupta explained.

“The attacker compromised the server(s) that these hot wallets were running on,” the Polygon CSO wrote on Friday. “Once inside the server, they could access the keys that were kept in plaintext for signing legit transactions. The server exploit was likely either SSH key compromise or social engineering. This is eerily similar to how Ronin was hacked.” The analyst further added:

This was not a ‘Blockchain Hack.’ It was a ‘Traditional Hack.’ I’ve been begging protocols to focus on traditional security too alongside blockchain security for months now…

Furthermore, an incident report written by the Harmony Protocol’s founder says “the team has found evidence that private keys were compromised, leading to the breach of our Horizon bridge — Funds were stolen from the Ethereum side of the bridge.” The Harmony founder also noted that “confidentiality is key to maintain integrity as part of this ongoing investigation — The omission of specific details is to protect sensitive data in the interest of our community.”

What do you think about the Harmony exploit for $100 million? Let us know what you think about this subject in the comments section below.

Read Entire Article
spot_img

Related Posts

Crypto Expert Turns Bullish On Bitcoin, Predicts Quantitative Easing Will Begin Soon

Crypto expert Michaël van de Poppe has made a bullish case for Bitcoin as he alluded to macroeconomic factors that could soon play out in the flagship crypto’s favor In line with this, he urged

Bitfinex whales bolster Bitcoin holdings by 6% amid recent price surge

Quick Take Over the past few days, Bitfinex has recorded a substantial 6% increase in Bitcoin (BTC) long positions held by whales — totaling a staggering 48,615 BTC Analyzing Bitfinex whale

Bitcoin Bottom In? Retracement From $73,800 Is Deeper And Took Longer To Form

Some analysts were frightened by the recent drop in Bitcoin prices Though the coin is showing signs of strength, multiple leveraged longs were liquidated early this week In a post on X, one

Is Buying XRP A Profitable Trade? Crypto Analyst Says It’s “Dead”

XRP has largely had a lackluster price movement in recent months, although it continues to show promise for real-world utility Particularly, the price of XRP was recently rejected at $066 after a

Dutch authorities arrest suspect in ZKasino gambling scam, seize $12.2 million in assets

The Netherlands’ Fiscal Information and Investigation Service (FIOD) announced the arrest of a 26-year-old suspected to be involved in the ZKasino decentralized gambling platform scam

Analyst: Gold and Silver Set to Rally Amidst a Collapse of the US Financial System

Egon von Greyerz, a former banker and gold analyst, claims that gold and silver are set for a price rally amidst an upcoming collapse of the US financial system Von Greyerz states that interest rates
- Advertisement -spot_img