Cryptocurrency platform Wormhole hit in $320 million hack

Representational image depecting cybersecurity protection
(Image credit: Shutterstock)

A vulnerability in Wormhole, a cryptocurrency platform that allows users to convert one token into another, has been exploited by attackers who managed to “mint” some 120,000 wETH, or Wrapped Ether, on the Solana network. 

In layman’s terms, a “wrapped” token is one that does not reside on its native blockchain (for example, bitcoin can only be shared on the Ethereum network if it’s wrapped).

Of those 120,000 wETH, the attackers transferred 93,750 Ether back to its native platform - at the time of going to press, the value of wETH is around $318 million, while the value of the transferred Ether is $248 million

Too late to patch

Since the disclosure of the attack, Wormhole’s developers have taken the network down and patched up the flaw. 

deBridgeFinance co-founder, Alex Smirnov, claims the developers actually spotted the vulnerability earlier, and had a patch ready, but did not have enough time to deploy it. This wasn’t a malware issue, and no endpoints in the network were compromised.

Wormhole took to social media to offer the attackers a “whitehat contract” and a $10 million bounty reward for discovering the flaw, if they return all of the funds. A whitehat contract would mean there would be no criminal investigation into the attack. However, as The Record reports, chances are the law enforcement will get involved, either way. 

Furthermore, the organization says it will add more funds to the platform, to “ensure wETH is backed 1:1”. We don’t know where the funds would come from.

Wormhole acts as a bridge from Solana towards multiple chains, including Ethereum, Terra, Binance Smart Chain, Polygon, Avalanche, and Oasis. In total, it has more than $1 billion locked. 

With respect to the number of tokens stolen in the attack, the Wormhole breach will most likely become the second-largest Decentralized Finance (DeFi) platform attack of all time, and the biggest one this year. It’s only February, though. 

  •  You might also want to check out our list of the best firewalls right now

Via: The Record

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Ethereum
Hackers steal over $1bn in one of the biggest crypto thefts ever
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
cryptocurrency
It's been a huge year for criminals stealing cryptocurrency - and North Korea was largely to blame
A VPN runs on a mobile phone placed on a laptop keyboard
SonicWall firewalls hit by worrying cyberattack
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
The best free firewall
Palo Alto warns another major firewall hack has been detected
Latest in Security
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
DeepSeek
Fake DeepSeek installers are infecting your device with dangerous malware
AI tools.
Not even fairy tales are safe - researchers weaponise bedtime stories to jailbreak AI chatbots and create malware
Data leak
Top California sperm bank suffers embarrassing leak
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
ransomware avast
Billions of credentials were stolen from businesses around the world in 2024
Latest in News
Stability AI 3D Video
Stability AI’s new virtual camera turns any image into a cool 3D video and I’m blown away by how good it is
The Google Wallet app with a mode for kids shown on-screen.
Google Wallet’s new kid-friendly payment system is a win for parents
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
Google Pixel 9a
Google is delaying the Pixel 9a to fix a mystery “component quality issue”
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works
ExpressVPN mobile app and Aircove
ExpressVPN ‘reduces workforce’ for the second time in two years