Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Rubic DEX aggregator hack leads to $1.4m of user funds stolen

Altszn.com by Altszn.com
December 25, 2022
in Blockchain
0
Rubic DEX aggregator hack leads to $1.4m of user funds stolen
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


Cross-chain decentralized finance (DeFi) protocol Rubic was compromised, resulting in funds stored in its user’s addresses being siphoned out and transferred to the hackers.

On Dec. 25, Rubic protocol announced that one of its routing contracts was compromised and all contracts would be stopped until the situation is fully understood. The announcement read:

The protocol’s creators also advised their users to revoke contract authorization through the revoke.cash tool. A Twitter thread by blockchain cybersecurity firm PeckShield explains that a vulnerability in the Rubic protocol led to a loss of $1.41 million worth of funds directly from the wallets that authorized its smart contracts.

The exploiter address received the funds from the Uniswap decentralized exchange (DEX) in transactions involving the USD Coin (USDC) stablecoin. PeckShied explained that the hack was made possible due to mistakenly adding USDC into supported routers. Furthermore, “a lack of validation in ruterCallNative” also allowed malicious contract use.

A quick smart contract analysis with the help of chatGPT suggests that the ruterCallNative function contains numerous potential vulnerabilities, including invalidated input for the “_params” and “_data” parameters. These could allow an attacker to pass malicious input that could result in incorrect or unintended behaviour.

Furthermore, the “_gateway” parameter passed to the function is unrestricted, potentially allowing an attacker to create a contract and have it executed by the RubicProxy contract.

Indeed, the attacker deployed a custom smart contract that was used in the attack. The decoded bytecode shows the 337 lines of code that allowed the attacker to perform the attack as efficiently as possible.

The hacker’s address received first a 1,161.55 ethereum (ETH) transfer and another 26.88 ETH transfer, both from the Uniswap protocol siphoning out exclusively USDC and exchanging it for wrapped ethereum (WETH). All of this WETH was later sent to an on-chain mixer and sanctioned entity Tornado Cash to anonymize the ill-gotten funds.

On-chain analysis shows that $1.45 million worth of incoming transactions sent to the coin anonymization service originated from the hacker’s address — on a total incoming value for the service of about $2.9 million. In other words, about half of the assets sent to the mixer today were sent by the exploiter.

Rubic DEX aggregator hack leads to $1.4m of user funds stolen - 1
Tornado.Cash incoming transfers processed on Dec. 25. Hacker’s address is on the right. | Courtesy of Arkham Intelligence

Despite the hacker’s funds being such a significant portion of the service’s incoming transaction volume, their anonymity is still substantial. The deposit may be among the $2 million withdrawals from Tornado Cash processed today or among the $174 million worth of assets still deposited in the smart contract.

Tornado Cash is a now-illegal DeFi protocol that allows users to perform anonymous transfers on the Ethereum blockchain. The protocol uses zero-knowledge proofs (ZK-proofs) to hide transactions’ input and output addresses. It is difficult for third parties to determine the identity of the parties involved in the transaction or the specific purpose of the transfer.

Tornado Cash is an open-source project built on top of the Ethereum blockchain and accessible to anyone with an Ethereum wallet. Users can interact with the Tornado Cash contract using their Ethereum wallet or a web interface still available through the decentralized hosting service InterPlanetary File System (IPFS). They can perform anonymous transfers of ETH or tokens compliant with the ERC-20 standard by sending their funds to the Tornado Cash contract and withdrawing them to a new address.

The news follows recent reports that North Korean hackers have stolen around $1.2 billion in cryptocurrency and other virtual assets over the past five years. Most of those hacks happened in 2021 alone.


Follow Us on Google News



Read More: crypto.news

Tags: 1.4MAggregatorBlockchainDEXFundsHackleadsRubicstolenuser
ADVERTISEMENT

Recent

Silk Road Founder Ross Ulbricht to Bitcoiners: ‘Freedom is Worth the Struggle’

Silk Road Founder Ross Ulbricht to Bitcoiners: ‘Freedom is Worth the Struggle’

May 30, 2025
China’s state-backed think tank considers Bitcoin reserve, Sony Bank goes Web3: Asia Express

China’s state-backed think tank considers Bitcoin reserve, Sony Bank goes Web3: Asia Express

May 30, 2025
Solana rally capped by SOL token unlock and memecoin decline

Solana rally capped by SOL token unlock and memecoin decline

May 29, 2025

Categories

  • Bitcoin (4,564)
  • Blockchain (10,863)
  • Crypto (8,809)
  • Dark Web (455)
  • DeFi (8,141)
  • Ethereum (4,595)
  • Metaverse (6,892)
  • Monero (253)
  • NFT (1,139)
  • Solana (4,933)
  • Web3 (19,945)
  • Zcash (470)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    Silk Road Founder Ross Ulbricht to Bitcoiners: ‘Freedom is Worth the Struggle’

    Silk Road Founder Ross Ulbricht to Bitcoiners: ‘Freedom is Worth the Struggle’

    May 30, 2025
    China’s state-backed think tank considers Bitcoin reserve, Sony Bank goes Web3: Asia Express

    China’s state-backed think tank considers Bitcoin reserve, Sony Bank goes Web3: Asia Express

    May 30, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 106,024.00
    • ethereumEthereum (ETH) $ 2,613.65
    • tetherTether (USDT) $ 0.999998
    • xrpXRP (XRP) $ 2.21
    • bnbBNB (BNB) $ 672.48
    • solanaSolana (SOL) $ 164.17
    • usd-coinUSDC (USDC) $ 0.999796
    • dogecoinDogecoin (DOGE) $ 0.208416
    • tronTRON (TRX) $ 0.272057
    • cardanoCardano (ADA) $ 0.709369
    • staked-etherLido Staked Ether (STETH) $ 2,614.27
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 105,774.00
    • suiSui (SUI) $ 3.46
    • wrapped-stethWrapped stETH (WSTETH) $ 3,130.84
    • hyperliquidHyperliquid (HYPE) $ 32.43
    • chainlinkChainlink (LINK) $ 14.60
    • avalanche-2Avalanche (AVAX) $ 21.69
    • stellarStellar (XLM) $ 0.273581
    • leo-tokenLEO Token (LEO) $ 9.11
    • the-open-networkToncoin (TON) $ 3.35
    • bitcoin-cashBitcoin Cash (BCH) $ 409.21
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • hedera-hashgraphHedera (HBAR) $ 0.177392
    • usdsUSDS (USDS) $ 0.999639
    • litecoinLitecoin (LTC) $ 91.74
    • wethWETH (WETH) $ 2,615.78
    • wrapped-eethWrapped eETH (WEETH) $ 2,786.16
    • polkadotPolkadot (DOT) $ 4.22
    • moneroMonero (XMR) $ 332.90
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.996660
    • bitget-tokenBitget Token (BGB) $ 5.09
    • pepePepe (PEPE) $ 0.000013
    • ethena-usdeEthena USDe (USDE) $ 0.999817
    • pi-networkPi Network (PI) $ 0.689928
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 105,957.00
    • whitebitWhiteBIT Coin (WBT) $ 31.21
    • daiDai (DAI) $ 0.999971
    • uniswapUniswap (UNI) $ 6.48
    • aaveAave (AAVE) $ 248.41
    • bittensorBittensor (TAO) $ 409.85
    • nearNEAR Protocol (NEAR) $ 2.66
    • aptosAptos (APT) $ 4.98
    • okbOKB (OKB) $ 51.75
    • jito-staked-solJito Staked SOL (JITOSOL) $ 198.31
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.17
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • tokenize-xchangeTokenize Xchange (TKX) $ 35.24
    • crypto-com-chainCronos (CRO) $ 0.093081
    • ondo-financeOndo (ONDO) $ 0.878020
    • internet-computerInternet Computer (ICP) $ 5.18
    • bitcoinBitcoin (BTC) $ 106,024.00
    • ethereumEthereum (ETH) $ 2,613.65
    • tetherTether (USDT) $ 0.999998
    • xrpXRP (XRP) $ 2.21
    • bnbBNB (BNB) $ 672.48
    • solanaSolana (SOL) $ 164.17
    • usd-coinUSDC (USDC) $ 0.999796
    • dogecoinDogecoin (DOGE) $ 0.208416
    • tronTRON (TRX) $ 0.272057
    • cardanoCardano (ADA) $ 0.709369
    • staked-etherLido Staked Ether (STETH) $ 2,614.27
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 105,774.00
    • suiSui (SUI) $ 3.46
    • wrapped-stethWrapped stETH (WSTETH) $ 3,130.84
    • hyperliquidHyperliquid (HYPE) $ 32.43
    • chainlinkChainlink (LINK) $ 14.60
    • avalanche-2Avalanche (AVAX) $ 21.69
    • stellarStellar (XLM) $ 0.273581
    • leo-tokenLEO Token (LEO) $ 9.11
    • the-open-networkToncoin (TON) $ 3.35
    • bitcoin-cashBitcoin Cash (BCH) $ 409.21
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • hedera-hashgraphHedera (HBAR) $ 0.177392
    • usdsUSDS (USDS) $ 0.999639
    • litecoinLitecoin (LTC) $ 91.74
    • wethWETH (WETH) $ 2,615.78
    • wrapped-eethWrapped eETH (WEETH) $ 2,786.16
    • polkadotPolkadot (DOT) $ 4.22
    • moneroMonero (XMR) $ 332.90
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.996660
    • bitget-tokenBitget Token (BGB) $ 5.09
    • pepePepe (PEPE) $ 0.000013
    • ethena-usdeEthena USDe (USDE) $ 0.999817
    • pi-networkPi Network (PI) $ 0.689928
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 105,957.00
    • whitebitWhiteBIT Coin (WBT) $ 31.21
    • daiDai (DAI) $ 0.999971
    • uniswapUniswap (UNI) $ 6.48
    • aaveAave (AAVE) $ 248.41
    • bittensorBittensor (TAO) $ 409.85
    • nearNEAR Protocol (NEAR) $ 2.66
    • aptosAptos (APT) $ 4.98
    • okbOKB (OKB) $ 51.75
    • jito-staked-solJito Staked SOL (JITOSOL) $ 198.31
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.17
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • tokenize-xchangeTokenize Xchange (TKX) $ 35.24
    • crypto-com-chainCronos (CRO) $ 0.093081
    • ondo-financeOndo (ONDO) $ 0.878020
    • internet-computerInternet Computer (ICP) $ 5.18