$5 000 000 USD

JUNE 2024

GLOBAL

LOOPRING

DESCRIPTION OF EVENTS

"Loopring is a software running on Ethereum that aims to incentivize a global network of users to operate a platform that enables the creation of new types of crypto asset exchanges."

 

High transaction fees are "exactly what Loopring aims to remedy, by delivering a digital economy that empowers its users while still giving them complete control over their assets. With Loopring, people no longer have to sacrifice efficiency and affordability to take advantage of Ethereum’s network security."

 

"Loopring (LRC) is an Ethereum Layer-2 scaling protocol that enables the building of decentralized exchanges which rival centralized exchanges in terms of performance. The network can handle up to 1,000 times more trades per second than Ethereum with each one costing a mere fraction of a cent."

 

"Loopring's zkRollup L2 solution offers the same security guarantees as Ethereum mainnet, with a big scalability boost: throughput increased by 1000x, and cost reduced to just 0.1% of L1. Ethereum is now unleashed. One year ago, we launched the first zkRollup on Ethereum - now we put its power in your pocket. Smooth orderbook trading, AMMs, and global payments, right from the Loopring wallet."

 

"Most notably, Loopring claims its platform will allow exchanges built on top of it to sidestep the slow speeds and high costs associated with decentralized exchanges on Ethereum through the use of a newer type of cryptography called zero-knowledge rollups, or zkRollups."

 

"This is exactly why the app asks you to setup multiple guardians and even notifies you to do so if you haven't every time you log in, that's alot of people who ignored the warnings daily and this unfortunate event happened."

 

SlowMist estimates $5m.

 

"Ethereum Layer 2 protocol Loopring posted on Twitter that the some Loopring Smart Wallets were targeted in a security breach. The attack exploited wallets with only one Guardian, specifically the Loopring Official Guardian. The hacker initiated a Recovery process, falsely posing as the wallet owner to reset ownership and withdraw assets. The attack succeeded by compromising Loopring's 2FA service, allowing the hacker to impersonate the wallet owner and gain approval for the Recovery from the Official Guardian. Subsequently, the attacker transferred assets out of the affected wallets."

 

"A few hours ago, some Loopring Smart Wallets were targeted in a security breach. The attack exploited wallets with only one Guardian, specifically the Loopring Official Guardian. The hacker initiated a Recovery process, falsely posing as the wallet owner to reset ownership and withdraw assets.

 

The attack succeeded by compromising Loopring's 2FA service, allowing the hacker to impersonate the wallet owner and gain approval for the Recovery from the Official Guardian. Subsequently, the attacker transferred assets out of the affected wallets.

 

We are actively collaborating with Mist security experts to determine how our 2FA service was compromised. To protect our users, we have temporarily suspended Guardian-related and 2FA-related operations. Following this action, the compromise has ceased.

 

Loopring is working with law enforcement and professional security teams to track down the perpetrator. We will continue to provide updates as soon as the investigation progresses."

 

"Due to a recent security breach involving Loopring's two-factor authentication (2FA) service, the pre-scheduled smart contract auto-upgrade on the Ethereum mainnet, originally set for June 12th, has been postponed. We will proceed with the upgrade at a later date and will announce this date ahead of time."

 

"If you've experienced asset loss during the Loopring Smart Wallet compromise event - please contact us at foundation at loopring dot org

 

We are actively collaborating with security experts, centralized exchanges (CEX), and law enforcement to recover the lost funds. Any progress will be communicated through our official channels immediately.

 

Also - be aware and watch out for impersonators and scammers in the replies who are trying to capitalize off this event."

 

"If you've experienced asset loss during the Loopring Smart Wallet compromise event - please contact us at foundation at loopring dot org

 

We are actively collaborating with security experts, centralized exchanges (CEX), and law enforcement to recover the lost funds. Any progress will be communicated through our official channels immediately."

Loopring provides wallet software, which has a default setting of only a single official guardian. While the software provided daily notices requesting users to set up additional guardians, and multiple sources online including a post from Vitalik Buterin provided additional guidance on doing so, many users chose not to and remained with the default security setup. On June 8th, a malicious actor found a way to bypass the two-factor authentication which Loopring provided through their official guardian. This allowed them to access many wallets of Loopring users, which they subsequently drained. Loopring has postponed an upgrade to their smart contract and is reportedly working with law enforcement, centralized exchanges, and different security experts to recover lost funds.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.