<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=OpSec_Staking_Security_Private_Key_Breach</id>
	<title>OpSec Staking Security Private Key Breach - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=OpSec_Staking_Security_Private_Key_Breach"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=OpSec_Staking_Security_Private_Key_Breach&amp;action=history"/>
	<updated>2026-05-30T06:43:55Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=OpSec_Staking_Security_Private_Key_Breach&amp;diff=6292&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/opsecstakingsecurityprivatekeybreach.php}} {{Unattributed Sources}}  OpSec Ecosystem Logo/HomepageThe OpSec Ecosystem is a privacy-focused network dedicated to making operations on the cloud very seamless and efficient. Their staking contract was breached due to a private key which was leaked. A few hours later, a Twitter post was made requesting users to...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=OpSec_Staking_Security_Private_Key_Breach&amp;diff=6292&amp;oldid=prev"/>
		<updated>2024-10-25T20:03:10Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/opsecstakingsecurityprivatekeybreach.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Opseccomputer.jpg&quot; title=&quot;File:Opseccomputer.jpg&quot;&gt;thumb|OpSec Ecosystem Logo/Homepage&lt;/a&gt;The OpSec Ecosystem is a privacy-focused network dedicated to making operations on the cloud very seamless and efficient. Their staking contract was breached due to a private key which was leaked. A few hours later, a Twitter post was made requesting users to...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/opsecstakingsecurityprivatekeybreach.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Opseccomputer.jpg|thumb|OpSec Ecosystem Logo/Homepage]]The OpSec Ecosystem is a privacy-focused network dedicated to making operations on the cloud very seamless and efficient. Their staking contract was breached due to a private key which was leaked. A few hours later, a Twitter post was made requesting users to migrate to a V2 version of the contract by sending their V1 tokens to a new address. Despite having comments disabled and coming at the time of the breach, this post was apparently from the legitimate OpSec team. Those users who did not transfer their tokens within the 2 week period appear to have lost their funds, however they may be reimbursed on a case by case basis.&amp;lt;ref name=&amp;quot;slowmisthackedarchive-15116&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;opseccloudtwitter-15146&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;opseccloudtwitter-15147&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;opseccloudtwitter-15148&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;opseccloudtwitter-15149&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;opseccloudtwitter-15150&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;opsec-15151&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;opseccloudtwitter-15152&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;opseccloudtwitter-15153&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;opseccloudtwitter-15154&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;opseccloudtwitter-15155&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About the OpSec EcoSystem ==&lt;br /&gt;
&amp;quot;OpSec Ecosystem is a privacy-focused network dedicated to making operations on the cloud very seamless and efficient.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;OpSec decentralized cloud solutions range from high level nodes, light speed router devices, GPUs and hosting services.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;OpSec's decentralized architecture is built upon advanced cloud network technology and it forms the foundation of a secure and resilient computing environment.&lt;br /&gt;
&lt;br /&gt;
OpSec Nodes, the backbone of this infrastructure, allow users to deploy projects autonomously or collaboratively, fostering a diverse and inclusive ecosystem.&lt;br /&gt;
&lt;br /&gt;
OpSec's decentralized computing architecture is meticulously crafted to redefine the landscape of distributed systems. Whether you are hosting decentralized apps, deploying blockchain nodes, or remotely accessing your servers, OpSec makes sure that your journey is characterized by security, independence, and innovative forward-thinking.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;The OpSec staking contract was maliciously upgraded, allowing the attacker to withdraw and sell OPSEC tokens worth approximately 59 ETH (around $182,000).&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - OpSec Staking Security Private Key Breach&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|July 10th, 2024 7:13:47 AM MDT&lt;br /&gt;
|Malicious Blockchain Transaction&lt;br /&gt;
|The malicious transaction on Ethereum which is reportedly due to a breached private key, allowing the attacker to change the ownership of the staking contract to a wallet that they control.&lt;br /&gt;
|-&lt;br /&gt;
|July 10th, 2024 10:25:00 AM MDT&lt;br /&gt;
|OpSec Announcement Tweet&lt;br /&gt;
|The OpSec Twitter account posts an update to let followers know that an hour ago, external attackers breached the security of the $OPSEC staking contract and stole some funds. The team is quickly working to address the issue by withdrawing liquidity and migrating to a new contract address. They are requesting $OPSEC holders to send their tokens to a recovery address to receive updated V2 tokens. Funds are safe, and the marketing and development wallets are secure and being migrated to new wallets. Post-migration improvements include better security, no contract dumps, lower tax rates, and higher liquidity. Users who held $OPSEC tokens before July 10, 2024, 15:15 UTC are safe. The team will provide more details soon and is currently holding an AMA on Telegram. The message is authentic, and the team warns to be cautious of scams.&lt;br /&gt;
|-&lt;br /&gt;
|July 21st, 2024 12:12:00 PM MDT&lt;br /&gt;
|Continual Work On Relaunch&lt;br /&gt;
|The team posts continual updates to Twitter about the relaunch of their new v2 token. The new $OPSEC V2 contract will be audited by Hacken starting Wednesday, with completion expected by Friday. This will be followed by the relaunch. The V2 contract will have 0% buy and sell tax, increased liquidity, and improved security. For DEX users, send your V1 tokens to the V2 recovery address by July 26, 2024. CEX users should wait for further instructions as the transition will be managed by exchanges. V2 tokens will be distributed through a claim-based method to reduce gas fees, minimize risks, and manage trading pressure. An eligibility form will be available on CloudVerse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;A private key with access to make changes to the staking contract was compromised. This allowed the attacker to change the ownership of the staking contract from a team wallet to the attackers wallet.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
&amp;quot;At the time of the Breach the compromised tokens had a value of approximately $800,000.&lt;br /&gt;
&lt;br /&gt;
At the time that the attacker was able to trade these tokens for Ethereum from the liquidity pool, he was only able to do so for an approximate value of 59 Ethereum.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The total amount at risk has been estimated at $800,000 USD. The total amount lost has been estimated at $182,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;An hour ago, we experienced a security breach by external attackers, resulting in the theft of some funds from our staking contract.&lt;br /&gt;
&lt;br /&gt;
We are taking immediate measures to address the situation by withdrawing liquidity from the current $OPSEC contract. We need to act fast to recover and migrate the contract address (CA).&lt;br /&gt;
&lt;br /&gt;
To support this urgent migration, we need your help. Please send your $OPSEC tokens to the recovery address below to receive V2 tokens during the migration.&lt;br /&gt;
&lt;br /&gt;
$OPSEC Recovery Address: 0x362538c16a2868038AE72B608c080B6433f979C9&lt;br /&gt;
&lt;br /&gt;
Snapshot of current holders of V2 airdrop was taken. Please do not buy current $OPSEC token.&lt;br /&gt;
&lt;br /&gt;
Key Points:&lt;br /&gt;
&lt;br /&gt;
Funds are safe: You can relax and follow the instructions provided above. Marketing and development wallets are secure: We are migrating them to isolated fresh wallets.&lt;br /&gt;
&lt;br /&gt;
Post-migration benefits include:&lt;br /&gt;
&lt;br /&gt;
- Increased contract security&lt;br /&gt;
- No contract dumps&lt;br /&gt;
- Lower tax rates&lt;br /&gt;
- Higher liquidity&lt;br /&gt;
&lt;br /&gt;
User Safety: All users are safe. If you are an $OPSEC holder who did not purchase after 15:15 UTC, Wednesday, 10 July 2024, you are completely safe. We will handle individual cases as needed.&lt;br /&gt;
&lt;br /&gt;
Upcoming Updates:&lt;br /&gt;
&lt;br /&gt;
More details will be shared ASAP regarding the root cause of the breach.&lt;br /&gt;
&lt;br /&gt;
An AMA is live NOW on telegram addressing the situation.&lt;br /&gt;
&lt;br /&gt;
Rest assured, this message is from the internal OpSec team. Our Twitter account has not been hacked.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;Our team is diligently compiling a comprehensive overview of token distribution and transactions during and after the breach. This involves developing a script and processing extensive data for a thorough understanding beyond a simple snapshot. Once all data is gathered and analyzed, it will be transparently shared with the community. We have completed the stakers' data and vestments, and the CEXs typeform is progressing well. We will crosscheck addresses promptly to be ready for launch.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;slowmisthackedarchive-15116&amp;quot;&amp;gt;[https://web.archive.org/web/20240808214427/https://hacked.slowmist.io/?c=&amp;amp;page=2 SlowMist Hacked - SlowMist Zone] (Accessed Aug 27, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;opseccloudtwitter-15146&amp;quot;&amp;gt;[https://twitter.com/OpSecCloud/status/1811074256220115283 @OpSecCloud Twitter] (Accessed Aug 28, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;opseccloudtwitter-15147&amp;quot;&amp;gt;[https://twitter.com/OpSecCloud/status/1811088220416872701 @OpSecCloud Twitter] (Accessed Aug 28, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;opseccloudtwitter-15148&amp;quot;&amp;gt;[https://twitter.com/OpSecCloud/status/1811703139461968218 @OpSecCloud Twitter] (Accessed Aug 28, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;opseccloudtwitter-15149&amp;quot;&amp;gt;[https://twitter.com/OpSecCloud/status/1812099494067994978 @OpSecCloud Twitter] (Accessed Aug 28, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;opseccloudtwitter-15150&amp;quot;&amp;gt;[https://twitter.com/OpSecCloud/status/1812879593717854400 @OpSecCloud Twitter] (Accessed Aug 28, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;opsec-15151&amp;quot;&amp;gt;[https://www.opsec.computer/ OpSec] (Accessed Aug 28, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;opseccloudtwitter-15152&amp;quot;&amp;gt;[https://twitter.com/OpSecCloud/status/1813550565839839482 @OpSecCloud Twitter] (Accessed Aug 28, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;opseccloudtwitter-15153&amp;quot;&amp;gt;[https://twitter.com/OpSecCloud/status/1814027927224525245 @OpSecCloud Twitter] (Accessed Aug 28, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;opseccloudtwitter-15154&amp;quot;&amp;gt;[https://twitter.com/OpSecCloud/status/1815087398918717902 @OpSecCloud Twitter] (Accessed Aug 28, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;opseccloudtwitter-15155&amp;quot;&amp;gt;[https://twitter.com/OpSecCloud/status/1817656985380176158 @OpSecCloud Twitter] (Accessed Aug 28, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>