<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=OASIS_Application_Wallet_Software_Exploited</id>
	<title>OASIS Application Wallet Software Exploited - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=OASIS_Application_Wallet_Software_Exploited"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=OASIS_Application_Wallet_Software_Exploited&amp;action=history"/>
	<updated>2026-06-10T10:06:15Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=OASIS_Application_Wallet_Software_Exploited&amp;diff=5218&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/oasisapplicationwalletsoftwareexploited.php}} {{Unattributed Sources}}  OASIS App (Now Summer.Fi)Oasis, a frontend for the MakerDAO project, aimed to provide a trusted entry point for users to deploy their capital in DeFi. Users could borrow Dai or buy additional collateral to increase their exposure to crypto by opening a Maker Vault and depositing 25+ crypto collateral...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=OASIS_Application_Wallet_Software_Exploited&amp;diff=5218&amp;oldid=prev"/>
		<updated>2023-11-23T19:39:06Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/oasisapplicationwalletsoftwareexploited.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Oasisapp.jpg&quot; title=&quot;File:Oasisapp.jpg&quot;&gt;thumb|OASIS App (Now Summer.Fi)&lt;/a&gt;Oasis, a frontend for the MakerDAO project, aimed to provide a trusted entry point for users to deploy their capital in DeFi. Users could borrow Dai or buy additional collateral to increase their exposure to crypto by opening a Maker Vault and depositing 25+ crypto collateral...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/oasisapplicationwalletsoftwareexploited.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Oasisapp.jpg|thumb|OASIS App (Now Summer.Fi)]]Oasis, a frontend for the MakerDAO project, aimed to provide a trusted entry point for users to deploy their capital in DeFi. Users could borrow Dai or buy additional collateral to increase their exposure to crypto by opening a Maker Vault and depositing 25+ crypto collaterals. However, Oasis faced controversy when a previously unknown vulnerability in the design of its admin multisig access allowed the retrieval of assets stolen in the February 2022 Wormhole bridge exploit. Following a court order, Oasis cooperated in the retrieval using the multisig and a court-authorized third party. The incident sparked concerns about the platform's upgradability and its potential implications for decentralized finance. Oasis responded by making its automation contracts fully decentralized and immutable, removing the ability to upgrade any associated contracts. The platform has also ultimately rebranded themselves as Summer Finance (summer.fi).&lt;br /&gt;
&lt;br /&gt;
This is a global/international case not involving a specific country.&amp;lt;ref name=&amp;quot;funominalletwitter-12435&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;oasisapparchive-12436&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;oasisappblogarchive-12437&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;oasisappblogarchive-12438&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;summerfi-12439&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;chrisbduckytwitter-12440&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-12441&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;oasisapparchive-12442&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;web3isgoinggreat-12443&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coindesk-12444&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;redditold-12445&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About OASIS.App ==&lt;br /&gt;
&amp;quot;Borrow Dai and Multiply your exposure to crypto. Open a Maker Vault, deposit 25+ crypto collaterals. Either borrow Dai or buy additional collateral to increase your exposure. Connect a wallet to start.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Oasis mission is to provide the best and most trusted entry point to deploy your capital. We are building Oasis.app to let our users benefit from all of the potential in DeFi. Our team is made of passionate thinkers and builders.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Oasis is a frontend for the MakerDAO project, which was originally started as part of MakerDAO but later spun into a separate entity, though it still appears to enjoy preferred status by MakerDAO.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;why were some upgradeable in the first place? Well this is a simple answer - we pride ourselves at Oasis on great UX and trust, and ultimately users want to know that 1) when they set something&amp;quot; &amp;quot;like automation up, they trust that it will always work for them, and 2) they are doing this to optimise or protect their funds - they don't want lose their assets due to a bug or another hacker stealing them. So yes, we had certain contracts that were upgradeable, such as&amp;quot; &amp;quot;the exchange contract, so that if a bug was discovered in say 1inch, which we use to perform the swaps for automation, or perhaps a third party could pass in something that caused a risk to user funds, that we would be able to move quickly and remove this risk to users.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Our team first became aware of the possibility to assist in the retrieval of the assets after a Whitehat group reached out to the team on the evening of Thursday 16th February 2023, that showed it would be possible to retrieve the assets and provided a Proof of Concept on how it could be achieved. What occurred on 21st February 2023 was only possible due to a previously unknown vulnerability in the design of the admin multisig access. We stress that this access was there with the sole intention to protect user assets in the event of any potential attack, and would have allowed us to move quickly to patch any vulnerability disclosed to us. It should be noted that at no point, in the past or present, have user assets been at risk of being accessed by any unauthorised party.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;On 21st February 2023, we received an order from the High Court of England and Wales to take all necessary steps that would result in the retrieval of certain assets involved with the wallet address associated with the Wormhole Exploit on the 2nd February 2022. This was carried out in accordance with the requirements of the court order, as required by law, using the Oasis Multisig and a court authorised third party&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The stolen funds in question were the proceeds of the February 2022 Wormhole bridge exploit, in which attackers stole 120,000 wETH (then ~$326 million; now $192 million). After the hack, Wormhole's parent company Jump Crypto plugged the hole left by the hack with their own funds. Since then, the attackers have been moving the funds throughout the cryptocurrency ecosystem, even taking out a highly-leveraged position on in Lido-staked Ether last month.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;We can also confirm the assets were immediately passed onto a wallet controlled by the authorised third party, as required by the court order. We retain no control or access to these assets.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;We are thankful to the Whitehat group for their intervention, which represents an example of how important the community is in our space at this stage. Our mission keeps being to be the most trusted place to deploy and manage your capital in DeFi.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Ultimately, Jump was able to recover around $140 million via their &amp;quot;counter-exploit&amp;quot;. While many celebrated the recovery, some were concerned about the precedent of a so-called defi platform changing a smart contract to remove funds from a wallet at the direction of a court. Some described the upgradability as a &amp;quot;backdoor&amp;quot;.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Speaking of music industry rugs promoted by “celebrities” check out $OASIS&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;If they'd do it for Jump, what does that say about possible coercion via state actors?&amp;quot; wrote one trader on Twitter.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Are they so incompetent they cant make a proper multi-sig wallet or was this a deliberate backdoor. Either way you shouldn't be using anything made by this company.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Oasis released a defensive statement, writing that their cooperation in the recovery was &amp;quot;only possible due to a previously unknown vulnerability in the design of the admin multisig access&amp;quot;, and that &amp;quot;we will be making no further comment at this time&amp;quot;.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;We have now removed the ability to upgrade any of the contracts associated with Oasis Automation. This has been done by setting the authorized address to the 0x0, instead of the Oasis Multisig.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Our Automation contracts are now fully decentralized and IMMUTABLE.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;I want to give an update on the incident involving http://Oasis.app and the wormhole exploiter that occurred on Feb 21st. I'm aware we have been quite silent on the matter, but I would like to take the opportunity to clarify a few things.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;This means we can no longer upgrade any of the contracts, and as such, there is no way for the multisig (or any address/contract) to perform any operations similar to the one that happened a few weeks ago again.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;I want to reiterate something very clearly though, that was ignored heavily on the original statement; it was never our intention, or knowledge, that we could actually perform such an operation using the upgradable contracts the way that they were used. Yes we were aware&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;that we allowed some of our contracts to be upgradeable (more on this later), but not all of them - and the ones which were not upgradeable had multiple checks in place, as well as the users automation parameters, which we strongly believed prevented the type of  operation.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;what we were not aware of until Feb 16th was that the checks left open the possibility to perform the action that occurred AND still pass the immutable checks that were in place.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;It was a set of actions using a number of functions that we just didn't foresee. And because the main contracts that contain the checks were not upgradeable, it meant it was also not possible to just add these checks in now.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;So we have taken the only route we saw possible in making the 'Counter-Exploit' operation not possible again, and that is removing any ability to upgrade any of the contracts moving forward. So from now, all of the&amp;quot; &amp;quot;Oasis Automation contracts are fully immutable.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Your funds, your choice: put your capital to work while staying in full control, with no exceptions&amp;quot;&lt;br /&gt;
&lt;br /&gt;
This is a global/international case not involving a specific country.&lt;br /&gt;
&lt;br /&gt;
The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.&lt;br /&gt;
&lt;br /&gt;
Include:&lt;br /&gt;
&lt;br /&gt;
* Known history of when and how the service was started.&lt;br /&gt;
* What problems does the company or service claim to solve?&lt;br /&gt;
* What marketing materials were used by the firm or business?&lt;br /&gt;
* Audits performed, and excerpts that may have been included.&lt;br /&gt;
* Business registration documents shown (fake or legitimate).&lt;br /&gt;
* How were people recruited to participate?&lt;br /&gt;
* Public warnings and announcements prior to the event.&lt;br /&gt;
&lt;br /&gt;
Don't Include:&lt;br /&gt;
* Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.&lt;br /&gt;
* Anything that wasn't reasonably knowable at the time of the event.&lt;br /&gt;
There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - OASIS Application Wallet Software Exploited&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|February 16th, 2023&lt;br /&gt;
|Whitehat Group Report&lt;br /&gt;
|A whitehat group reaches out to the OASIS wallet to provide a Proof of Concept for extracting funds from a wallet on the OASIS blockchain.&lt;br /&gt;
|-&lt;br /&gt;
|February 21st, 2023&lt;br /&gt;
|Court Order Received&lt;br /&gt;
|The OASIS network reports that they received the court order on February 21st.&lt;br /&gt;
|-&lt;br /&gt;
|February 24th, 2023 2:22:53 PM MST&lt;br /&gt;
|Blog Post About Order&lt;br /&gt;
|The blog post is made about the transaction which was executed to freeze and return the funds associated with the Wormhole exploit.&lt;br /&gt;
|-&lt;br /&gt;
|February 24th, 2023 4:26:34 PM MST&lt;br /&gt;
|CoinDesk Article Published&lt;br /&gt;
|CoinDesk publishes an article on the exploit and court order.&lt;br /&gt;
|-&lt;br /&gt;
|February 24th, 2023 4:53:27 PM MST&lt;br /&gt;
|Reddit Discussion&lt;br /&gt;
|Reddit discussion begins which doesn't reflect well on the service. &amp;quot;Are they so incompetent they cant make a proper multi-sig wallet or was this a deliberate backdoor. Either way you shouldn't be using anything made by this company.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|March 9th, 2023 7:54:47 AM MST&lt;br /&gt;
|Upgradeability Removed&lt;br /&gt;
|The Oasis application upgradeability has been removed by setting the wallet which controls the upgrade to 0x0.&lt;br /&gt;
|-&lt;br /&gt;
|March 9th, 2023 10:57:00 AM MST&lt;br /&gt;
|Clarification And Patch&lt;br /&gt;
|The CEO Chris B reports that they have now made the contract fully immutible and provided the on-chain transaction.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost has been estimated at $140,000,000 USD.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;funominalletwitter-12435&amp;quot;&amp;gt;[https://mobile.twitter.com/funominalle/status/1506557173522137090 https://mobile.twitter.com/funominalle/status/1506557173522137090] (Jan 13, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;oasisapparchive-12436&amp;quot;&amp;gt;[https://web.archive.org/web/20220105135459/https://oasis.app/ Oasis.app] (Nov 23, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;oasisappblogarchive-12437&amp;quot;&amp;gt;[https://web.archive.org/web/20230401130223/https://blog.oasis.app/statement-regarding-the-transactions-from-the-oasis-multisig-on-21st-feb-2023/ &amp;lt;nowiki&amp;gt;[UPDATED] Statement Regarding The Transactions From The Oasis Multisig on 21st Feb 2023 - Oasis Blog&amp;lt;/nowiki&amp;gt;] (Nov 23, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;oasisappblogarchive-12438&amp;quot;&amp;gt;[https://web.archive.org/web/20230224220308/https://blog.oasis.app/statement-regarding-the-transactions-from-the-oasis-multisig-on-21st-feb-2023/ Statement Regarding The Transactions From The Oasis Multisig on 21st Feb 2023 - Oasis Blog] (Nov 23, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;summerfi-12439&amp;quot;&amp;gt;[https://summer.fi/ The best place to Borrow and Earn in DeFi] (Nov 23, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;chrisbduckytwitter-12440&amp;quot;&amp;gt;[https://twitter.com/chrisbducky/status/1633889732882227207 @chrisbducky Twitter] (Nov 23, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-12441&amp;quot;&amp;gt;[https://etherscan.io/tx/0x563a8cedc73c605316296f45d25de89ed647176ef536fbbdd8a78534b38cd590 Ethereum Transaction Hash (Txhash) Details | Etherscan] (Nov 23, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;oasisapparchive-12442&amp;quot;&amp;gt;[https://web.archive.org/web/20211030133730/https://oasis.app/about About Us] (Nov 23, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;web3isgoinggreat-12443&amp;quot;&amp;gt;[https://web3isgoinggreat.com/?id=oasis-rewrites-the-rules-for-jump-crypto Per a court order, Oasis rewrites the rules for Jump Crypto to recover stolen assets] (Nov 23, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coindesk-12444&amp;quot;&amp;gt;[https://www.coindesk.com/business/2023/02/24/oasis-exploits-its-own-wallet-software-to-seize-crypto-stolen-in-wormhole-hack/ Oasis Exploits Its Own Wallet Software to Seize Crypto Stolen in Wormhole Hack] (Nov 23, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;redditold-12445&amp;quot;&amp;gt;[https://old.reddit.com/r/CryptoCurrency/comments/11b62u4/oasis_exploits_its_own_wallet_software_to_seize/ Oasis Exploits its Own Wallet Software to Seize Crypto Stolen in Wormhole Hack : CryptoCurrency] (Nov 23, 2023)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>