<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Sunray_Finance_Malicious_Upgrade_And_Token_Minting</id>
	<title>Sunray Finance Malicious Upgrade And Token Minting - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Sunray_Finance_Malicious_Upgrade_And_Token_Minting"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Sunray_Finance_Malicious_Upgrade_And_Token_Minting&amp;action=history"/>
	<updated>2026-05-30T07:49:42Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Sunray_Finance_Malicious_Upgrade_And_Token_Minting&amp;diff=6389&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/sunrayfinancemaliciousupgradeandtokenminting.php}} {{Unattributed Sources}}  Sunray Finance Logo/HomepageSunray Finance offered a decentralized exchange on the Arbitrum blockchain. They claimed to have the backing of Japan's SoftBank, and their Twitter links to the SoftBank website, however SoftBank does not appear to have officially provided a public end...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Sunray_Finance_Malicious_Upgrade_And_Token_Minting&amp;diff=6389&amp;oldid=prev"/>
		<updated>2024-12-06T22:36:14Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/sunrayfinancemaliciousupgradeandtokenminting.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Sunrayfinance.jpg&quot; title=&quot;File:Sunrayfinance.jpg&quot;&gt;thumb|Sunray Finance Logo/Homepage&lt;/a&gt;Sunray Finance offered a decentralized exchange on the Arbitrum blockchain. They claimed to have the backing of Japan&amp;#039;s SoftBank, and their Twitter links to the SoftBank website, however SoftBank does not appear to have officially provided a public end...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/sunrayfinancemaliciousupgradeandtokenminting.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Sunrayfinance.jpg|thumb|Sunray Finance Logo/Homepage]]Sunray Finance offered a decentralized exchange on the Arbitrum blockchain. They claimed to have the backing of Japan's SoftBank, and their Twitter links to the SoftBank website, however SoftBank does not appear to have officially provided a public endorsement of their project. On October 29th, 2024, a new upgrade took place on their smart contract. The upgrade allowed for the minting of a massive number of tokens, which were immediately swapped. It is alleged that this activity has nothing to do with the Sunray Finance team and that the private key was compromised. It appears that a large chunk of the potentialy loot was lost to an arbitrage bot, which managed to insert an arbitrage trade, exploiting the difference in two separate liquidity pools. However, the attacker still made off with close to $3m. The Sunray Finance team appears to be working with the Binance security team on a potential recovery, however there have been no new updates since early November. The Sunray Finance website is presently offline, however their Twitter account still exists.&amp;lt;ref name=&amp;quot;cointelegraph-16932&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;matchsystemstwitter-16933&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coinness-16934&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cryptopolitan-16935&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sunrayfinancearchive-16936&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sunraydextwitter-16937&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;chaincatcher-16938&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;web3isgoinggreat-16939&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;tenarmoralerttwitter-16940&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;arbiscan-16941&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;arbiscan-16942&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;arbiscan-16943&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;arbiscan-16944&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sunraydextwitter-16945&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sunraydextwitter-16946&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cryptorank-16947&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sunraydextwitter-16948&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sunraydextwitter-16949&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Sunray Finance ==&lt;br /&gt;
&amp;quot;Sunray DEX is a new attempt at building a blockchain-based market on Arbitrum. The DEX was created with the involvement of SoftBank, though the project is not listed on its portfolio page. The Sunray DEX X account also communicated in a way that singled it out as a crypto outsider, taking a long time to launch in a dynamic environment where new tokens and DEX build up their activity much faster.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;SUN is a reserve currency that provides an open financial service platform. Focus on co building SUNRAYDEX's global business, supported by SoftBank.TBCAsoft.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The Sunray DEX has a landing page, but most of its features are still inactive. The Sunray Finance protocol promised an extremely high passive income of 299% for SUN, with the addition of the ARC governance token.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;SUNRAY FINANCE experienced a private key compromise, allowing the exploiter to gain control of the SUN and ARC tokens and sell them off, draining the funds from DEX pairs. So far, the attacker has stolen approximately $2.855 million.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Sunray Finance Malicious Upgrade And Token Minting&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|September 4th, 2024 1:53:24 AM MDT&lt;br /&gt;
|Last Capture Of Sunray Finance Website&lt;br /&gt;
|The last capture of the Sunray Finance website, which appears to be offline.&lt;br /&gt;
|-&lt;br /&gt;
|October 29th, 2024 9:45:06 PM MDT&lt;br /&gt;
|Smart Contract Upgraded&lt;br /&gt;
|The smart contract is upgraded to a malicious version, which allows for the minting of new SUN tokens.&lt;br /&gt;
|-&lt;br /&gt;
|October 29th, 2024 9:46:35 PM MDT&lt;br /&gt;
|Malicious Token Generation&lt;br /&gt;
|The new malicious smart contract mints 200,000,000,000,000,000,000,000 SUN token.&lt;br /&gt;
|-&lt;br /&gt;
|October 29th, 2024 9:47:37 PM MDT&lt;br /&gt;
|Newly Minted Token Swap&lt;br /&gt;
|The attacker swaps half of the newly minted tokens using one of the main liquidity providers. In the same block, an arbitrage bot automatically swaps using the other liquidity option. Multiple sources claim that the attacker overlooked this second source of liquidity, however the attacker maintained half of their SUN tokens, suggesting they actually intended to swap on both liquidity pools.&lt;br /&gt;
|-&lt;br /&gt;
|October 30th, 2024 5:15:00 AM MDT&lt;br /&gt;
|Transfer Update Post&lt;br /&gt;
|The team reports that they &amp;quot;are currently working hard to restore&amp;quot; &amp;quot;SUN and ARCToken treasury assets&amp;quot; which were transfered at noon that day.&lt;br /&gt;
|-&lt;br /&gt;
|October 30th, 2024 3:20:18 PM MDT&lt;br /&gt;
|CryptoPolitan News Article&lt;br /&gt;
|According to CryptoPolitan, &amp;quot;Neither Sunray Finance nor Sunray Swap have reported a hack through their channels. The investigation is ongoing, as the native SUN token is now practically worthless. Sunray Finance claimed its smart contracts were audited, but the project’s social media suggest it was not prepared enough for the latest DEX and Web3 challenges and attacks.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|October 30th, 2024 8:24:00 PM MDT&lt;br /&gt;
|TenArmor Alert Posted&lt;br /&gt;
|TenArmor posts an alert about the suspicious attack, with losses estimated at $2.7m.&lt;br /&gt;
|-&lt;br /&gt;
|October 31st, 2024 8:46:00 AM MDT&lt;br /&gt;
|Update Posted Twitter&lt;br /&gt;
|The Sunray Finance team posts an update with an official statement about the exploit and path forward.&lt;br /&gt;
|-&lt;br /&gt;
|November 4th, 2024 11:11:00 PM MST&lt;br /&gt;
|Another Twitter Update&lt;br /&gt;
|The Sunray Finance team posts to notify that they are wroking with the Binance security team.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost has been estimated at $2,885,000 USD.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;Decentralized exchange Sunray Finance has been drained of $2.855 million due to a private key compromise, blockchain security firm CertiK reported on X via its CertiK Alert account. The hacker acquired ownership of SUN and ARC tokens and minted a large number of tokens before dumping them.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Perpetuals trading protocol Sunray Finance on Arbitrum was exploited for $2.7 million on Oct. 30, when an attacker managed to upgrade the protocol’s contract and mint two-hundred sextillion (200,000,000,000 trillion) of the protocol’s native SUN token, according to a report from blockchain security firm TenArmor.&lt;br /&gt;
&lt;br /&gt;
The attacker subsequently swapped half of the tokens for $2.1 million worth of Tether (USDT). The attack collapsed the SUN price.&lt;br /&gt;
&lt;br /&gt;
The exploiter appears to have overlooked the fact that there was a second liquidity pool for SUN. In the very next block, an arbitrage bot purchased approximately 90 sextillion SUN from the pool that the attacker had dumped the coins into, which it then sold into the second pool at a profit of approximately $560,000 worth of Ether (ETH). This collapsed the price in the second pool as well.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;Sunray Treasury Asset Transfer Statement, Treasury as a public asset of the community, is secure, transparent, publicly traceable, and we are accelerating and working hard to recover all data. Please be patient and wait for specific details&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;At present, we have contacted the Binance/BM security team and everyone is patiently waiting. We are actively handling the work related to this incident and believe that there will be results soon&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;cointelegraph-16932&amp;quot;&amp;gt;[https://cointelegraph.com/news/btc-scammers-sunray-finance-crypto-sec https://cointelegraph.com/news/btc-scammers-sunray-finance-crypto-sec] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;matchsystemstwitter-16933&amp;quot;&amp;gt;[https://twitter.com/MatchSystems/status/1856666253462495237 @MatchSystems Twitter] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coinness-16934&amp;quot;&amp;gt;[https://coinness.com/en/news/32526 CoinNess] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cryptopolitan-16935&amp;quot;&amp;gt;[https://www.cryptopolitan.com/malicious-smart-contract-causes-2-8m-in-sun-token-losses-on-arbitrum/ https://www.cryptopolitan.com/malicious-smart-contract-causes-2-8m-in-sun-token-losses-on-arbitrum/] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;sunrayfinancearchive-16936&amp;quot;&amp;gt;[https://web.archive.org/web/20240904075324/https://www.sunray.finance/ SUNRAY] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;sunraydextwitter-16937&amp;quot;&amp;gt;[https://twitter.com/SUNRAY_DEX/status/1851583772531306605 @SUNRAY_DEX Twitter] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;chaincatcher-16938&amp;quot;&amp;gt;[https://www.chaincatcher.com/en/article/2149616 SUNRAY private key leaked, attackers have stolen $2.855 million - ChainCatcher] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;web3isgoinggreat-16939&amp;quot;&amp;gt;[https://www.web3isgoinggreat.com/single/sunray-finance-hack Sunray Finance hacked for $2.7 million] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;tenarmoralerttwitter-16940&amp;quot;&amp;gt;[https://twitter.com/TenArmorAlert/status/1851812530320216479 @TenArmorAlert Twitter] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;arbiscan-16941&amp;quot;&amp;gt;[https://arbiscan.io/tx/0x0e111a7070c7006fde55070eb9b9c0b8006abe371a91bd283859499b2ca6372e Arbitrum One Transaction Hash (Txhash) Details | Arbitrum One] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;arbiscan-16942&amp;quot;&amp;gt;[https://arbiscan.io/tx/0x1a7518af17b2f82e98b9ea6fa8e94bf4e8485390b7de7793ea0017ffbc426675 Arbitrum One Transaction Hash (Txhash) Details | Arbitrum One] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;arbiscan-16943&amp;quot;&amp;gt;[https://arbiscan.io/tx/0x6bf01fc425d2591ac34d41b6a193580079e2506206405841f9cb38881fbb74b2 Arbitrum One Transaction Hash (Txhash) Details | Arbitrum One] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;arbiscan-16944&amp;quot;&amp;gt;[https://arbiscan.io/tx/0x14b2c23397b5aa4239620cd1ad4c4ea3872f59c54feefdadd63ca3d36ae4af4f Arbitrum One Transaction Hash (Txhash) Details | Arbitrum One] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;sunraydextwitter-16945&amp;quot;&amp;gt;[https://twitter.com/SUNRAY_DEX/status/1851999280074002851 @SUNRAY_DEX Twitter] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;sunraydextwitter-16946&amp;quot;&amp;gt;[https://twitter.com/SUNRAY_DEX/status/1853681557057503697 @SUNRAY_DEX Twitter] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cryptorank-16947&amp;quot;&amp;gt;[https://cryptorank.io/funds/softbank/portfolio?page=1 SoftBank Portfolio | CryptoRank.io] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;sunraydextwitter-16948&amp;quot;&amp;gt;[https://twitter.com/SUNRAY_DEX @SUNRAY_DEX Twitter] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;sunraydextwitter-16949&amp;quot;&amp;gt;[https://twitter.com/SUNRAY_DEX/status/1728445452318892097 @SUNRAY_DEX Twitter] (Accessed Dec 6, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>