ThorChain loses $7.6M in ‘Chaosnet’ exploit, offers hacker a bounty to return funds

Popular cross-chain decentralized exchange, ThorChain, has suffered a multimillion-dollar breach.

Estimates as to the scale of the damage vary, with ThorChain revising the initial estimate that 13,000 ETH (worth $25.1 million) had been stolen down to 4,000 ETH (roughly $7.6 million) as a ballpark for damages.

In the ThorChain community Telegram channel, administrators have indicated the project has the funds needed to cover users’ stolen assets, but articulated a preference for the hacker to return the stolen funds in exchange for a bug bounty.

“While the treasury has the funds to cover the stolen amount, we request the attacker get in contact with the team to discuss return of funds and a bounty commensurate with the discovery,” a Telegram post stated, adding that user funds “will be available when the issue has been patched & the network resumes.”

ThorChain has since tweeted that its preliminary roadmap to recovery is underway, announcing that after the vulnerability is patched and the network restarted, Ether will be donated to liquidity provider pools to reimburse impacted users. From there, the team plans to engage security firms to have its contracts audited.

As of this writing, the ThorChain network remains halted.

Blockchain cybersecurity firm, Halborn Security, is compiling a proposal to the ThorChain community for “Advance Persistent Protection,” offering up a team of up to half a dozen “ethical security engineers working to break every update on ThorChain.”

Related: A RUNE with a view: How smart crypto traders caught a 48% price pump

Thorchain entered into its guarded “Chaosnet” launch during April, facilitating cross-chain swaps across the Bitcoin, Ethereum, Litecoin, Bitcoin Cash, and Binance Chain networks.

DeFi Watch founder Chris Blec said the staged “raise the caps” launch of ThorChain had prevented an even greater loss of funds.

Today’s attack is not the first time ThorChain has been targeted by hackers during its Chaosnet deployment, with the protocol losing at least $140,000 worth of assets last month.

Source: Read Full Article