The Harmony Heist: US $100M Stolen💰

QuillAudits - Web3 Security 🛡️
QuillHash
Published in
3 min readJun 27, 2022

Events Under the Spotlight 🔎

Harmony Protocol’s Horizon bridge hacked, $100M stolen

  • The Harmony Protocol bridge suffered a hack that led to a loss of $100M.
  • The bridge exploiter stole 11 different ERC-20 tokens and 13,100 Ether from the bridge.
  • The stolen funds were transferred to other ERC-20 tokens to two other wallets to swap via UniSwap and other DEXs back to ETH.
  • The protocol is suspected to suffer private key compromise.

Convex Finance’s DNS domain was hijacked

  • Convex Finance’s DNS domain was hijacked, directing users to approve malicious contracts for some interactions on the site.
  • A total of 215 ETH were lost during the event.
  • Users were asked to contact the support team for reimbursement.
  • The reason is known to be a compromised employee.

Vulnerability spotted in WhaleLoans protocol

  • A vulnerability was discovered in the WhaleLoans protocol’s stable pool implementation.
  • An attacker took a flash loan to exploit the vulnerability and earned ~12K (5,946 BUSD and 5,964 USDT).
  • The problem pertains to be associated with the k-value check.

PandoraChain DAO flash loaned for $128k

  • PandoraChain DAO suffered a flash loan attack and was hacked for $128K.
  • The hacker manipulated the $PCD price through a flash loan to get a large amount of $PCD locked tokens.
  • Then unlocked the $PCD tokens multiple times and swapped them for USDT.

Justcows on BNB Chain fell for a Rug Pull

  • Justcows on BNB Chain rugged investors for $5M.
  • The project party distributed a large amount of BUSD to tens of thousands of addresses in the form of currency mixing.
  • Some of the funds were transferred to HunterSwap, and some entered the exchange.

To the Numerophiles out there 🔢

  • Binance Signs Football Star Cristiano Ronaldo for NFT Push

Source

Word on the Block📦

Pegging

Versus Series🛡️

Staking VS Yield farming

Stay updated with the latest happenings in the blockchain world; join our Discord community here🤝.

--

--

QuillAudits - Web3 Security 🛡️
QuillHash

Building the QuillAI Network: AI Agents Safeguarding Web3. Leading Smart Contract Audit Firm with $30B+ secured. Join our security squad builders 🛡️