Wormhole token bridge loses $321M in largest hack so far in 2022

Wormhole token bridge loses $321M in largest hack so far in 2022

The Wormhole token bridge experienced a security exploit today, resulting in the loss of 120,000 wETH tokens ($321 million) from the platform.

Wormhole is a token bridge that allows users to send and receive crypto between Ethereum, Solana, BSC, Polygon, Avalanche, Oasis, and Terra without the use of a centralized exchange (CEX). This is the largest crypto hack of 2022 so far and the second largest DeFi hack to date. The Wormhole team has offered a $10M bug bounty for the return of the funds.

Our top trading bots

The hack took place on the Solana side of the bridge and there are fears Wormhole’s bridge to Terra could be similarly vulnerable.

The Wormhole team has assured the community that its ETH supply would be replenished to “ensure wETH is backed 1:1,” but there is no word yet on where those funds will come from or when.

The hack took place at 6:24pm UTC on Feb. 2. The attacker minted 120,000 wETH (WETH) on Solana, then redeemed 93,750 WETH for ETH worth $254 million onto the Ethereum network at 6:28pm UTC. The hacker has since used some funds to buy SportX (SX), Meta Capital (MCAP), Finally Usable Crypto Karma (FUCK), and Bored Ape Yacht Club Token (APE).

The remaining WETH was swapped for SOL and USDC on Solana. The hacker’s Solana wallet currently holds 432,662 SOL ($44 million).

No other assets or chains served by Wormhole have been reported affected, but smart contract auditing firm Certik said in a report today that “It is possible that Wormhole’s bridge to the Terra blockchain shares the same vulnerability as their Solana bridge.”

The Wormhole team contacted the hacker through their Ethereum address to offered to let the hacker keep $10 million worth of funds stolen if the remaining funds are returned.

“This is the Wormhole Deployer: We noticed you were able to exploit the Solana VAA verification and mint tokens. We’d like to offer you a whitehat agreement, and present you a bug bounty of $10 million for exploit details, and returning the wETH you’ve minted. You can reach out to us at contact@certus.one”

As of the time of writing, wETH tokens sent across the bridge are not yet redeemable while the Wormhole team attempts to fix the exploit.

Wormhole token bridge loses $321M in largest hack so far in 2022

This is the second smart contract exploit on a token bridge in a week. On Jan. 28, Qubit Finance’s QBridge was exploited for $80 million on BSC. It is also reminiscent of the Poly Network hack last August wherein $610 million in crypto was stolen off the platform. In that case, nearly all of the funds were returned by the whitehat hacker.

Related: $2.5B in stolen BTC from Bitfinex hack awakens

The frequency of smart contract hacks on token bridges serves to validate Vitalik Buterin’s Jan. 7 warning that there are “fundamental security limits of bridges.” The Ethereum co-founder’s admonition was within the context of a 51% attack on Ethereum, but his advice was well-timed as he pointed out the general vulnerability apparent on bridges that send tokens across layer-1 blockchains.

Keep reading upon Cointelegraph
This bullish Ethereum options trade targets $3.1K ETH price with zero liquidation risk
Ether price (ETH) spent the last two months stuck in a rut and even the most bullish trader will admit that the possibility of trading above $4,400 in the...
NFT firm Dropp GG set to launch ‘geo-minting’ and ‘mixed reality events’
Solana-based augmented reality and NFT platform Dropp GG is developing geographical-based NFT minting and “mixed reality events” tied to the Metaverse.The...
FTX announced as naming rights sponsor of Australian Blockchain Week 2022
FTX Trading Limited (FTX) will be the naming rights sponsor for Australian Blockchain Week 2022, which will run from March 21 to 25. Blockchain Australia...
DeFi sector tokens offer shelter as Bitcoin falls below $48.5K
The cryptocurrency market slid lower on Dec. 28 as the price of Bitcoin (BTC) lost nearly $4,000 in value in a matter of hours with bulls now looking to...
Top 5 cryptocurrencies to watch this week: BTC, ETH, MATIC, ALGO, EGLD
Bitcoin (BTC) and most altcoins sold off on Dec. 4 with massive deleveraging seen in the crypto derivatives markets. Data suggests more than $2.5 billion...
French startup brings vintage wines to the NFT market
Many exciting developments are coming to the space of nonfungible tokens, or NFTs, ranging from metaverse NFTs to fantasy soccer digital collectible cards...
The future is Bitcoin according to South Park creators
South Park, the animated TV series that often tackles topical issues with a comedic twist, showed Bitcoin being used as a mainstream means of payment in...
An inside look at the moral and technical considerations of crypto social media
Following Vitalik Buterin’s call for more social application use cases on Ethereum earlier this summer, multiple crypto companies voiced intentions to build...
Bitcoin's $100K price target returns as BTC price breaks out of bull pennant
Bitcoin (BTC) looks poised to pursue a run-up towards $100,000 as its price breaks out of a classic bullish structure.Dubbed as the Bull Pennant, the setup...
BREAKING: Coinbase plans to raise $1.5B via debt offering
Coinbase, the largest cryptocurrency exchange in the United States, is planning to raise $1.5 billion via a debt offering, the company officially announced Monday.The...
Swisscom will become a Chainlink node operator
Switzerland-based telecommunications company Swisscom has said it will join Chainlink’s oracle network as a node operator. In a Thursday announcement, the...
Index Coop to include BadgerDAO in DPI DeFi index from August
BADGER, the governance token of Ethereum-powered Bitcoin yield protocol, BadgerDAO, will be included in Index Coop’s DeFiPulse Index (DPI) token from August.Index...
Default auditing for DeFi projects is a must for growing the industry
The radical opportunity presented by decentralized finance has garnered significant attention from investors and speculators alike. The total value locked...
SBI Crypto's Bitcoin mining pool goes public
SBI Crypto, the mining subsidiary of Japanese financial conglomerate SBI Holdings, has opened its mining pool to the general public. As one of the fruits...
ICO Benebit Team Disappeared With $2.7 million
The organizers of the ICO project Benebit disappeared with at least $2.7 million of investors' funds. According to other sources, the amount of money raised...