Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
Bitcoin Crime

DeFi Platform Qubit Finance Begs Hacker To Return $80 Million In Stolen Funds (zdnet.com) 70

Qubit Finance took to Twitter last night to beg hackers to return more than $80 million in stolen cryptocurrency this week. ZDNet reports: On Thursday, the DeFi platform said their protocol was exploited by a hacker who eventually stole 206,809 binance coins from Qubit's QBridge protocol, worth more than $80 million according to PeckShield. An hour after the first message, the company explained that they were tracking the exploiter and monitoring the stolen cryptocurrency. They noted that they contacted the hacker and offered them the maximum bug bounty in exchange for a return of the funds, something a number of other hacked DeFi platforms have tried to middling success. They shared multiple messages on Twitter that they purportedly sent to the hacker offering a bug bounty of $250,000 and begging for a return of the stolen funds.

"We propose you negotiate directly with us before taking any further action. The exploit and loss of funds have a profound effect on thousands of real people. If the maximum bounty offer is not what you are looking for, we are open to have a conversation. Let's figure out a situation," the Qubit Finance Team wrote. The company later explained in a blog post that their Qubit protocol "was subject to an exploit to our QBridge deposit function." [...] Blockchain security company CertiK released a detailed explanation of how the attack occurred and has been tracking the stolen funds as the hackers move them to different accounts. "For the non-technical readers, essentially what the attacker did is take advantage of a logical error in Qubit Finance's code that allowed them to input malicious data and withdraw tokens on Binance Smart Chain when none were deposited on Ethereum," CertiK explained.

This discussion has been archived. No new comments can be posted.

DeFi Platform Qubit Finance Begs Hacker To Return $80 Million In Stolen Funds

Comments Filter:
  • by iamnotx0r ( 7683968 ) on Friday January 28, 2022 @07:33PM (#62216453)
    Quit buying tulips.
  • may need an soldiers of fortune gun for hire ad to get anything from this hacker

    • by FuegoFuerte ( 247200 ) on Friday January 28, 2022 @08:15PM (#62216553)

      "In 1972, a crack commando unit was sent to prison by a military court for a crime they didn't commit. These men promptly escaped from a maximum security stockade to the Los Angeles underground. Today, still wanted by the government they survive as soldiers of fortune. If you have a problem, if no one else can help, and if you can find them....maybe you can hire The A-Team."

      Note: The A-Team works for cash and gold chains only. The A-Team does not accept or endorse crypto or other fake currencies, but they do pity the fool who has poured money into such dumpster fires.

  • by rsilvergun ( 571051 ) on Friday January 28, 2022 @07:41PM (#62216467)
    After a crypto hack is because the exchanges were able to step in and prevent those thieves from cashing in the currency. The only possibility they'll get any money back is if there's some Central authority that can prevent the hackers from getting to that 80 million.

    And why yes, this does mean that most cryptocurrencies are centrally managed now just like our federal reserve and banking system here in America.

    The beauty of crypto is that if it works it doesn't work and when it doesn't work it works except it still doesn't work. Did you get all that?
    • No that's not true, the ones where they got their money back were times when the hacker left some personally identifying info linking to his wallet address. If they don't do that they can spin it, move it to btc and cash out.
      • Return the funds. If they'd have the hackers wallet address and could drive the identity from it they wouldn't have just waited peacefully for the hacker to give the money back they would have given it to the authorities and let the hacker be arrested.

        The hackers in those cases return the money because it was worthless to them and that way they largely escaped prosecution because the people who are hacked wanted to keep things quiet and not involve the authorities if they could help it. Likely to avoid dr
        • Right, if they can link the wallet to you, you have to give it back. Otherwise you don't. They recovered around 50% of money taken from defi platforms so far but that number seems to be going down.
          • even if it's linked to the wallet. Crypto is tailor made for money laundering.

            What's happened in several cases is they didn't link the wallet or catch the guy, they knew which coins were stolen and the exchanges got together and did a 51% attack on the chain (using the large amount of crypto they hold for the purposes of being exchanges) to stop the trades going through and/or roll them back. That made the currency worthless (since they couldn't start up a money laundering engine), so they gave it back.
            • It wasn't an attack, it was a fork. Binance isn't going to do that over $80M
              • I mean a practical one. The point is the exchanges can exert centralized power. How they exert it is irrelevant. But when it happened to Coinbase they just stopped the trades. They didn't call it an attack, they just did it and nobody batted an eye.
                • Sure but we're talking about defi right now. If they don't know who the guy is, they won't be getting their money back.
        • Because I don't know, and I would love to find a citation.
          If you steal bitcoin via a hack, is the crime of bit coin theft punishable in the USA?
          I know the hacking yes, but the coins themselves.

  • ...to automate future hacks.

    The CEO of one company stated: "We don't necessarily want hacks, but if they are going to happen then we might as well set some standards to reduce work.

    This should reduce the amount of work we have to do in response by simplifying our request to the hackers to return funds. This also reduces work for the hackers by eliminating some of the things they do to try to hide their tracks, so we think they will buy into it also, it's a win-win"
  • Hmmmm.... (Score:3, Funny)

    by Anonymous Coward on Friday January 28, 2022 @07:49PM (#62216495)
    $80,000,000 vs $250,000? Let me think... nah, I'll take the $80,000,000.
  • by gweihir ( 88907 ) on Friday January 28, 2022 @07:50PM (#62216505)

    Something like this happens. I mean, is this kindergarten? Will they complain to the kindergarten teacher next that the hacker was mean to them?

  • Stupidity should be punished with maximum suffering lest it be encouraged.

  • Do any exchanges have a backup/cash reserve/deep pockets of any kind? Are they all one hack away from gone?
    • This was a bug, not a hack. This is why a 3 letter agency isn't mentioned ($80 million isn't chump change).

      Yes, they are one hack away from gone. Any protocol suffering an issue this bad where "protocol was exploited" IS the problem, is pretty much doomed and will go away...

      Exchange active trade reserves is another topic, the hot wallets used for active transfers to/from accounts.

  • Why should this affect “thousands of real people”?

    Surely the company is insured against loss and can make its users “whole”? And surely they can blacklist individual coins, flagging them up as “stolen” when an attempt is next made to transfer them on the blockchain?

    This company isnt stupid enough to act as a financial services company without insurance, right?

    • Re:Huh? (Score:4, Insightful)

      by sudonim2 ( 2073156 ) on Friday January 28, 2022 @10:47PM (#62216789)
      Remember the story of the libertarian asshole who refused to pay to be covered by the town fire department and also refused to allow his property to be incorporated into the town. Then his house caught fire and the fire department sat outside his house and watched as he sobbed while his house burnt to the foundations. This reminds me of that.
      • by Junta ( 36770 )

        Or the multiple goes of Libertarians going to create 'utopias', and end up appealing to the courts when they get screwed by suing people who wronged them. Suddenly they didn't have a purely capitalist solution and the courts they eschewed looked mighty good.

      • I have listened to the 911 tape of the guy screaming and pleading to save his home, while the fire department is watering the next door neighbors home. While this is not the case I recall, here is a similar citation https://www.nbcnews.com/id/wbn... [nbcnews.com]

        I recall your story also, I know it as a sovereign citizen not a libertarian.

        I dislike that Libertarians are clump up with Socialist and other groups ( I myself am a firm believer in capitalism, with higher taxes and free healthcare).

        • Sovereign citizens are a subgenre of the Libertarian/Bircher/Alt-right sphere. The Venn diagram isn't quite a circle, but it's close.

          Also, everywhere but in America, Libertarian means center-left. An overly reductive spectrum is Libertarian->Liberal->Social Democrats->Greens->Democratic Socialists->Socialist->Marxist/Leninist/Communist.

  • If crypto works as advertised, that is the transactions are totally anonymous, it is no better than stuffing mattresses with cash.

    As you try to use crypto to pay for something in the real world, lots of counter parties would have no incentive to protect your identity. Once the wallet and a real world identity is connected all the transactions are public. At that point it is way worse than stuffing mattresses with cash.

    This time the the platform got hacked.

    If it is truly anonymous, what would stop croo

    • by XXongo ( 3986865 ) on Friday January 28, 2022 @10:31PM (#62216765) Homepage

      If crypto works as advertised, that is the transactions are totally anonymous,

      But it isn't. Every cryptocurrency transaction is logged forever. Anonymity comes if, and only if, you have the ability to keep your wallet anonymous.

      Anonymity isn't a feature of the blockchain: it's something you maintain.

    • by ceoyoyo ( 59147 )

      If it is truly anonymous, what would stop crooks from holding some hostage and demanding ransom in crypto?

      Well, nothing really. Except the crooks have figured out that the whole kidnapping thing is almost as bad as the whole collecting the ransom thing used to be.

      People pay more to get their data back, and you can steal that online.

    • No crypto has ever been anonymous. The entire chain is publicly viewable. A prepaid debit card or a Cash app account you lied about your info on is more anonymous.
      • by kmoser ( 1469707 )
        Anonymous doesn't mean hidden. It just means it can't be traced back to an individual person or entity.
        • No, it only means that it can't be tracked inherently. But if it's tracked by some other means just once, everything you've done is suddenly public.
        • by Junta ( 36770 )

          You can't have anonymity without hiding the info in practice. In a ledger where *everything* is out in the open, it's pretty much a certainty that there's a transaction that ties a wallet to a human in an obvious way and from that point everything is connected. If you send me crypto for me to ship you a product, then I have your address. Once I use a parcel service, they know who I am because they had to get the parcel from me. Tying humans to wallets in practice is not that difficult for investigators a

  • by thogard ( 43403 ) on Friday January 28, 2022 @08:29PM (#62216579) Homepage

    At some point a hacker that is feed up with the energy waste or electronic waste or the general stupidity is going to crack one of these digital piggy banks and after pulling all of its loot will break all the keys.

    I'm surprised it isn't already happing every day.

    • by gweihir ( 88907 )

      The volume is just way too small still. But as soon as the other polluters start to fix their ways, CryptoCrap will be annihilated. That may take some time though. The way things are currently going, we probably will exceed 5C and then it does not matter anyways.

  • . . . ha ha ha ha ha ha ha ha . . .
    No, wait, I'm not done yet.
    . . . ha ha ha ha ha ha ha ha . . .
    Okay, I'm don-ha ha ha ha ha . . .

    All kidding aside, a crime has been committed here. There are real victims-ha ha ha ha ha
    (I'm sorry, I just can't do it with a straight face. Just the thought of all those people with all that money and all that greed making their common sense go right out the window, well - I don't know if "A fool and his money are soon parted" or "There is a sucker born every minute"

    • you really shouldn't make fun of the misfortune of these people and the DeFi

      AHAHAHAHAHA! my sides!!! Fucking dumb-asses, hahaha. Thinking begging will get the money back, AHAHAHAA

    • by GlennC ( 96879 )

      I don't know if "A fool and his money are soon parted" or "There is a sucker born every minute" makes more sense here

      I'd say they're both applicable.

      It would be even funnier if the hacker simply deleted the coins and they no longer exist.

  • Another day, another crypto hack [slashdot.org].

  • ... at the same time, right? Such a stereotypical naming for finance-wannabes. And just like with every other of those "platforms", chances are that "hacks" do not originate from some mysterious foreign party, but are part of the business model.
  • by Anonymouse Cowtard ( 6211666 ) on Friday January 28, 2022 @08:39PM (#62216609) Homepage
    I'm ready to talk and return 95%. But first I need the 250k. Contact me here.
  • Let me repeat that: ha ha ha!

  • I might be mistaken, but that has to be the most lucrative hack in history.

    Man, crypto is a joke.

  • by sudonim2 ( 2073156 ) on Friday January 28, 2022 @10:22PM (#62216749)

    Requiring an external actor to maintain the integrity of the blockchain means both that the blockchain is not secure and that it is not decentralized. It means the basic premise of crypto is false. So if crypto isn't a decentralized currency with no outside control, that means that crypto can only be a scam.

    As an aside, the reason the thieves accept the bug bounty money instead of the cash they've already stolen (even though it's questionable at best if they even violated any laws) is they ran into the fact that crypto is a scam. All crypto coins are inherently deflationary. The longer you leave your money in coins, the greater the value of those coins over time. This is a terrible attribute for a currency for a variety of reasons that I won't go in to now. But the relevant way this is terrible is that it means any exchange for crypto to real money inherently loses liquidity over time. That means there simply isn't enough dollars, pounds, euros, and francs in the exchange to cover the value of the crypto coins in the exchange. So while this thief stole $50+million of currency, that's only on paper. I'm guessing the actual liquidity available to them is much less than that. It probably would only be comparable to the bug bounty they're being offered.

    • by Junta ( 36770 )

      Note that while it is true the advocates advocating for it because it 'always goes up!' fail to understand that's what happened in the Great Depression, it's not guaranteed to be deflationary. See the last 3 months for example, where crypto-currency has been quite inflationary. While it's true that more of a particular instance of a crypto-currency can be prevented from creation, the other half, people caring less about that instance of crypto-currency, can of course make the currency inflationary.

      So in sh

      • Inflation/deflation is different than valuation. The valuation of the coins varies wildly and unpredictably. But the structure of the blockchain itself is such that fewer coins are minted over time as the rate of transactions go up. This means the money supply itself is shrinking, inducing deflation no matter what the particular valuation is. That's why it's inherently deflationary. It is designed to be artificially scarce.

        Now if the designers actually understood economics, which they clearly didn't, they

        • by Junta ( 36770 )

          In practice, inflation/deflation is not strictly a function of the number of units of currency, but is intrinsically linked to valuation.. By extension, you can't design the currency to maintain a 1-3% inflation rate, because you also have to factor in a complex universe of realities including international tensions, weather, disease impact, breakthroughs, fads, overall sentiment. The report about 7% inflation is based on CPI, not reports on the money supply.

          Sure assuming all those factors are level, then t

  • Anyone willing to pay the gas can call any method implemented by your contract, how is this hacking? Nobody exceeded their access limits..

    • by gweihir ( 88907 )

      Well, the one that wrote the code clearly is a hack, so there was some hack involved. Not on the side that apparently completely legitimately took the crapcoins though.

    • You can say that about most exploits...

      "It's not hacking. They just called a function with an undersized buffer and the code did what its programmed to do..."

      "It's not hacking. They just sent a perfectly valid request. Not their fault the code doesn't sanitize inputs..."

      With this hack they used an invalid address to exploit the contract code.

      • The statutes talk about gaining exceeding your authorized access to a computer. Everyone is allowed access to all the functions on contracts on the blockchain, its not your computer anyone is exploiting.

  • The key takeaway from the interview is: We need to be building at scale TODAY, not a decade from now which is what the new designs promise. By then it's too late. The frustrating part is we HAVE the renewable technology to get going but we're lacking political will.
  • DeFi hacks and cryptocurrency theft is growing like wildfire and even the most secure companies are getting infiltrated. If you have been a victim of these scams or hacks lately you can get help from Express Crypto Back, they specialize in tracking and recovering lost and stolen cryptocurrency.

The most exciting phrase to hear in science, the one that heralds new discoveries, is not "Eureka!" (I found it!) but "That's funny ..." -- Isaac Asimov

Working...