$60 000 USD

AUGUST 2024

GLOBAL

PARCL

DESCRIPTION OF EVENTS

"Speculate on Rising & Falling Real Estate Markets. Liquid exposure to real estate, for everyone. Earn a portion of trading fees by providing liquidity."

 

"Driven by Parcl Labs, Parcl price indexes are meticulously crafted from vast real estate data reservoirs, encompassing millions of data points from cities across the globe. As leaders in real estate analytics, Parcl Labs continually refines and recalibrates to ensure each index mirrors real-time, city-specific real estate values down to the median price per square foot. At Parcl, our commitment goes beyond numbers; it's about offering a transparent, authentic, and tradable view of the global urban landscape's evolving pulse."

 

"That element of the exploit appears to have been the most sophisticated & managed to circumvent multiple layers of account recovery methods, including 2fa."

 

"The smart contracts & exchange are secure and any exploits that occurred were limited to affected users clicking a compromised link and signing malicious transactions."

 

"it's common on solana drainers atm they use a technique called bitflipping

 

basically the original scam is - transfer 100 USDC out - then if A=1 transfer 100 USDC back

 

so the simulation shows 0 USDC moved

 

but when it's executed, they change A=0 so you don't get the USDC back"

 

"Preliminary analysis suggests the impact is contained to approx. 0.25% (25 basis points) or less of TVL equivalent. There was no known impact to any @ParclLimited or @ParclFoundation related systems or services."

 

According to DefiLlama, the TVL of Parcl is $23.9m. According to Parcl, up to 0.25% was potentially compromised, which is $59,750 or $60k.

 

"The website frontend of Solana ecosystem real estate trading protocol Parcl has been hacked, extracting tokens from users' Solana wallets and displaying fake transaction results in Phantom. Parcl’s official X account also appears to have been compromised, posting information related to PARCL rewards."

 

"Odaily Planet Daily reports that the Web3 security company Pocket Universe posted on X (formerly Twitter) indicating that they detected a hack on the front-end of the Parcl official website. The attackers are extracting tokens from users' Solana wallets and displaying false transaction results in Phantom."

 

"We've detected a frontend hack on @Parcl's official website. It drains tokens from your Solana wallet And displays fake tx results in Phantom. Let your friends know."

 

"The development team recognized this issue within 30 minutes of the incident, immediately initiated a freeze of the exchange, & took the required action to remediate DNS services."

 

"If your wallet was impacted, please submit a support ticket in the Parcl Discord; the moderators & community team are standing by to assist."

 

"The development team is working as fast as possible to secure and restore the Domain, re-open the exchange, and regain access to critical channels, namely the @Parcl twitter account.

 

We appreciate your patience & continued support"

Parcl is a decentralized smart contract service which allows investment/speculation on real estate prices. On August 19th, an attacker was able to gain access to the official Twitter account and domain management portal for Parcl. The attacker rerouted the Parcl website to their own server and posted a malicious website, which tricked users into signing undesirable transactions. Transactions would receive assets and claim to refund them back, however when actually executed, the transaction would not perform the refund due to a variable value which was changed. Due to the compromise of both the Twitter and main domain, users were tricked out of assets up to 0.25% of the TVL.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.