$490 000 USD

MAY 2024

GLOBAL

NORMIE

DESCRIPTION OF EVENTS

"ON A MISSION TO ONBOARD THE NEXT 1,000,000 $NORMIES TO BASE CHAIN."

 

"We are devoted to sharing our message to all the normies, and that's what the community expects from you, to help us transmit the message. May our vision be spread in a warm and human way, normie to normie."

 

"According to community feedback, the Base ecosystem's meme coin NORMIE has been attacked. The attacker exploited a design flaw in the NORMIE token's cross-chain bridge, manipulating the price on the Base Chain using flash loans. Since transactions with NORMIE on the Base Chain incur taxes, these taxes are automatically directed to a wallet controlled by the project team. The attacker injected a large amount of funds into this wallet via flash loans, significantly diluting the token's supply and causing a flash crash in the price."

 

"The vulnerability here is that any address receiving the same number of tokens as the deployer’s balance is added as a premarket_user. Any address in this list triggers a mint of NORMIE tokens to the contract itself."

 

"The attacker began by swapping 171,955 NORMIE tokens for 2 WETH. Later, they swapped 5 million NORMIE. This amount corresponded with the balance of the deployer account. By swapping an amount of tokens equal to the balance of the deployer, the address of the attack contract was added to the _premarket_user list, which enabled further manipulation."

 

"Next, the attacker flash-loaned 11,333,141 NORMIE tokens and swapped 9,066,513 for 65.97 WETH. This exchange was part of a strategy to manipulate the token supply and consequently, value. Repeated transfers of 2,266,628 NORMIE were made to the pair, followed by a calls to the skim() function to withdraw them."

 

"Since the attack contract was recognized as a premarket_user, the token contract added NORMIE tokens its own address (address(this))."

 

"When the balance exceeds a threshold, the swapAndLiquify mechanism is triggered to sell 4.65 million newly minted NORMIE each time."

 

"Finally, the attacker swapped 0.5 WETH for approximately 11,040,494 NORMIE at a lower price, which enable them to repay the flash loan of NORMIE tokens."

 

SlowMist reports $490k.

 

"PANews reported on May 26 that according to community user feedback, the price of NORMIE, the Meme coin of the Base ecosystem, plummeted by 87.3% due to a flash loan attack and is now reported at $0.005. The attacker took advantage of the design flaws of the NORMIE token cross-chain bridge to manipulate the price on the Base Chain through flash loans. Since NORMIE transactions on the Base Chain will be taxed, the tax will automatically go to the wallet controlled by the project party. The attacker injected a large amount of funds into the wallet through flash loans, thereby greatly diluting the token supply and causing the price to crash. Some users said that NORMIE has a vulnerability that allows attackers to mint new tokens. The total supply has now reached 214% of the theoretical maximum supply.

 

At present, the NORMIE team said that there are more than 500 ETH in its deployment wallet, which will be used to solve this problem. The team is actively contacting key partners to seek solutions and calls on users not to buy NORMIE tokens until further confirmation. The NORMIE team said that they are still deciding whether to restart or fork the project and will provide more updates as soon as possible."

 

"In an on-chain message to Normie’s deployer address on May 26, the hacker offered to return 90% of the stolen NORMIE tokens, stipulating that the remaining 10% be kept as a bug bounty with no reprisals.

 

The hacker also demanded that the stolen funds, along with the 600 ETH worth approximately $3,900 in the team’s dev wallet, be used to launch a new token to reimburse NORMIE holders.

 

“We will have to re-launch, yes,” stated Normie’s team via a newly established X account following the suspension of their main one. “That will come after we get our main Twitter account back and after we get the funds from the exploiter,” Normie added. However, the temporary account was also suspended shortly after that.

 

Meanwhile, the hacker wouldn’t compromise on their strict terms, insisting that a token relaunch must precede the return of funds. “The dev wallet made significantly more than I did during this exploit, and I have no other way to ensure that those funds are used appropriately,” they stated in another on-chain message."

Normies NFT is a NFT project with a goal of engaging millions of normal people onto the Base blockchain. Unfortunately, the project had a vulnerability which allowed an individual with the same balance as the team deployer wallet to execute special elevated permissions. The hacker later offered to return 90% of the funds if the project agreed to relaunch and distribute funds to affected users.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.