WHITEH CRYPTO INVEST
WHITEH

Crypto News

post cover

Binance CEO Says Exchange Recovered $450 Million From the Curve Finance Attack

Jamie Redman

13 August 2022

Following the recent Curve Finance attack, Binance CEO Changpeng Zhao announced that the exchange had recovered $450 million from hackers. The decentralized finance (defi) platform Curve saw roughly $570 million siphoned from the application on August 9.

Binance Boss Says Exchange Froze 83% of the Curve Finance Hack Funds, Domain Provider Says Exploit Was DNS Cache Poisoning

Four days ago, the crypto community was made aware that the Curve Finance front end was exploited. Curve fixed the situation but $570 million was removed from the defi protocol. The attackers, however, decided to send the funds to crypto exchanges. Binance CEO Changpeng Zhao (CZ) tweeted about the exploit the day it happened.

“Curve Finance had their DNS hijacked in the past hour,” CZ wrote. “Hacker put a malicious contract on the home page. When the victim approved the contract, it would drain the wallet. Damage is around $570K so far. We are monitoring.” In addition to Binance monitoring the situation, the exchange Fixedfloat managed to freeze some funds.

“Our security department has frozen part of the funds in the amount of 112 [ether]. In order for our security department to be able to sort out what happened as soon as possible, please email us,” Fixedfloat wrote the day of the hack. Then three days after the hack, on August 12, CZ explained at 1:07 a.m. (EST) that Binance recovered roughly 83% of the funds.

“Binance froze/recovered $450K of the Curve stolen funds, representing 83%+ of the hack,” CZ tweeted on Friday. “We are working with [law enforcement] to return the funds to the users. The hacker kept on sending the funds to Binance in different ways, thinking we can’t catch it,” CZ added.

Curve Finance retweeted CZ’s statement and noted earlier in the day that the team has a brief report from the domain provider [iwantmyname.com] and said: “In brief: DNS cache poisoning, not nameserver compromise,” Curve Finance explained while sharing the report. “No one on the web is 100% safe from these attacks. What has happened STRONGLY suggests to start moving to ENS instead of DNS.”

The domain provider iwantmyname.com’s report confirms Curve’s statements. “It appears that one customer’s domain was targeted,” iwantmyname.com’s disclosure report details. “Our external provider’s hosted DNS infrastructure was apparently compromised and the DNS records for this domain were changed to point to a cloned web server. Further investigation together with the external provider indicates that it was DNS Cache poisoning rather than any nameservers compromised.”

What do you think about Binance recovering $450 million from the Curve Finance hack? Let us know what you think about this subject in the comments section below.


News
$450 Million
$570K
Binance
Binance CEO
Changpeng Zhao
Curve
Curve fi frontend
Curve.finance
CZ
DeFi
Defi exploit
DNS Cache poisoning
ETH
Ethereum
Ethereum (ETH)
Fixedfloat
Funds
Hack
hacker's funds
iwantmyname.com
USDC
USDC funds

https://news.bitcoin.com/binance-ceo-says-exchange-recovered-450-million-from-the-curve-finance-attack/

Recent news

We are a cryptomining company. Our mission is to help people create cryptocurrency-based passive income to free up their time for love and creativity.

Copyright © 2021 Whiteh Inc. All rights reserved.