<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Tapioca_DAO_Private_Key_Social_Engineering</id>
	<title>Tapioca DAO Private Key Social Engineering - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Tapioca_DAO_Private_Key_Social_Engineering"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Tapioca_DAO_Private_Key_Social_Engineering&amp;action=history"/>
	<updated>2026-05-24T03:17:31Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Tapioca_DAO_Private_Key_Social_Engineering&amp;diff=6239&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/tapiocadaoprivatekeysocialengineering.php}} {{Unattributed Sources}}  Tapioca DAO Logo/HomepageTapiocaDAO is a decentralized organization creating an Omnichain stablecoin ecosystem, featuring components like Singularity, Big Bang, and Pearlnet, which enhance interoperability in DeFi. Its flagship stablecoin, USDO (OmniDollar), is designed to be decentralized...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Tapioca_DAO_Private_Key_Social_Engineering&amp;diff=6239&amp;oldid=prev"/>
		<updated>2024-10-21T16:57:01Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/tapiocadaoprivatekeysocialengineering.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Tapiocadao.jpg&quot; title=&quot;File:Tapiocadao.jpg&quot;&gt;thumb|Tapioca DAO Logo/Homepage&lt;/a&gt;TapiocaDAO is a decentralized organization creating an Omnichain stablecoin ecosystem, featuring components like Singularity, Big Bang, and Pearlnet, which enhance interoperability in DeFi. Its flagship stablecoin, USDO (OmniDollar), is designed to be decentralized...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/tapiocadaoprivatekeysocialengineering.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Tapiocadao.jpg|thumb|Tapioca DAO Logo/Homepage]]TapiocaDAO is a decentralized organization creating an Omnichain stablecoin ecosystem, featuring components like Singularity, Big Bang, and Pearlnet, which enhance interoperability in DeFi. Its flagship stablecoin, USDO (OmniDollar), is designed to be decentralized, censorship-resistant, and scalable, utilizing innovative mechanisms to ensure liquidity and efficiency across multiple networks. On October 18th, the network suffered from a social engineering attack where malware was installed on one of the primary key-holders through a phishing attack. This enabled the minting of a huge number of stablecoin tokens and a subsequent draining of the emergency fund of Tapioca (TAP) tokens. In a rare event, the team managed to reverse attack the hacker and recover 1000 ETH, which is the vast majority of the stolen funds. The situation is ongoing.&amp;lt;ref name=&amp;quot;rektnews-16187&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;0xteuntwitter-16188&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;tapiocadaotwitter-16189&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;arbiscan-16190&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;arbiscan-16191&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;arbiscan-16192&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;arbiscan-16193&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zachxbttwitter-16194&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;officerciatwitter-16195&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coingecko-16196&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;tapioca-16197&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;tapiocadocs-16198&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About TapiocaDAO ==&lt;br /&gt;
TapiocaDAO is a decentralized autonomous organization (DAO) represented by a Cayman Islands Foundation, which created a decentralized Omnichain stablecoin ecosystem, comprised of multiple sub-protocols, which includes; Singularity, the first-ever Omnichain isolated money market, Big Bang, an Omnichain CDP Stablecoin Creation Engine, Yieldbox, the most powerful token vault ever created, tOFT (Tapioca Omnichain Wrapper[s]) which transforms any fragmented asset into a unified Omnichain asset, twAML, an economic incentive consensus mechanism, and Pearlnet, the self-sovereign Omnichain verifier network.&lt;br /&gt;
&lt;br /&gt;
Omnichain interoperability focused on unifying DeFi's now trademark fragmented liquidity &amp;amp; UX, enabled through the LayerZero modular generalized messaging network, facilitated the creation of Tapioca's Omnichain CDP stablecoin creation engine, Big Bang, enabling users to mint Tapioca's unstoppable OmniDollar, USDO, with gas token &amp;amp; liquid staking token collateral from multiple networks in a chain agnostic manner. Current stablecoins are little more than store credits due to their lack of native interoperability, whereas USDO through the LayerZero OFT (Omnichain Fungible Token) super-standard can exist on any EVM or non-EVM. Tapioca's isolated money market, Singularity, also powered by LayerZero, empowers users on dozens of EVM &amp;amp; non-EVM networks to lend, borrow, and leverage up yield bearing assets. Pearlnet, a LayerZero Decentralized Verifier Network (DVN), allows the Tapioca ecosystem to achieve Omnichain interoperability &amp;amp; composability while minimizing trust and remaining self sovereign to avoid the costly mistakes of cross-chain protocols of the past. &lt;br /&gt;
&lt;br /&gt;
USDO, or the OmniDollar, is the first over-collateralized, decentralized &amp;amp; censorship resistant Omnichain U.S. Dollar pegged stablecoin, built to conquer the stablecoin trilemma of price stability, censorship resistance, and scalability, as well as to fill the current void of a lack of a truly unstoppable and scalable stablecoin. USDO offers an entirely new paradigm to decentralized stablecoins by only employing decentralized gas tokens &amp;amp; liquid staking derivatives to remain censorship resistant while also being capitally efficient, and utilizes a novel incentive program, DAO Share Options (DSO), to self-perpetuate USDO. twAML or Time Weighted Average Magnitude Lock, is a novel economic incentive consensus mechanism used to power DSO's novel oTAP call option incentive. These call option incentives enable Tapioca to capture protocol owned liquidity (POL), which in turn is utilized by the Tapioca DAO to self propagate USDO's liquidity depth on the open market. This enables USDO to become a scalable &amp;amp; decentralized U.S. Dollar stablecoin.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Tapioca DAO Private Key Social Engineering&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|October 18th, 2024 4:09:49 AM MDT&lt;br /&gt;
|Infinite USDO Mint Exploit&lt;br /&gt;
|The attacker mints a near infinite amount (315,522,735,360,502,617.7346702) of the USDO stablecoin.&lt;br /&gt;
|-&lt;br /&gt;
|October 18th, 2024 4:56:37 AM MDT&lt;br /&gt;
|First Attack Transaction&lt;br /&gt;
|The first attack transaction on arbitrum, which transfers 15,000,000 TAP tokens to the attacker.&lt;br /&gt;
|-&lt;br /&gt;
|October 18th, 2024 4:58:11 AM MDT&lt;br /&gt;
|Second Attack Transaction&lt;br /&gt;
|The second attack transaction on arbitrum, which transfers 11,773,539.252740904036736306 TAP tokens to the attacker.&lt;br /&gt;
|-&lt;br /&gt;
|October 18th, 2024 5:07:28 AM MDT&lt;br /&gt;
|Third Attack Transaction&lt;br /&gt;
|The third attack transaction on arbitrum, which transfers 2,896,327.580071485527554571 TAP tokens to the attacker.&lt;br /&gt;
|-&lt;br /&gt;
|October 18th, 2024 5:16:00 AM MDT&lt;br /&gt;
|0xTuen Tweet&lt;br /&gt;
|Twitter user 0xTuen posts to warn about the potential compromise of the platform.&lt;br /&gt;
|-&lt;br /&gt;
|October 18th, 2024 5:29:00 AM MDT&lt;br /&gt;
|officer_cia Tweet&lt;br /&gt;
|officer_cia posts about the exploit of the smart contract to seek confirmation.&lt;br /&gt;
|-&lt;br /&gt;
|October 18th, 2024 6:11:00 AM MDT&lt;br /&gt;
|ZachXBT Connections&lt;br /&gt;
|ZachXBT makes a post about how the exploit in the TapiocaDAO may be related to some other recent compromises, including Masa, Nahmii, Serenity Shield, Happy365Global, MurAll, Nexera&lt;br /&gt;
|-&lt;br /&gt;
|October 18th, 2024 11:33:00 AM MDT&lt;br /&gt;
|Tapioca DAO Announcement&lt;br /&gt;
|Tapioca DAO makes an announcement about the exploit, that they were socially engineered, and about the active ongoing war room which they have set up to deal with the incident.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost has been estimated at $4,400,000 USD.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;Seems that the following address managed to exploit Emergency Rescue function on one of the Vesting contracts deployed by the Tapioca Deployer.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;He drained 27mln $TAP in two transactions. Sold that in one go resulting in ~591 $ETH &lt;br /&gt;
&lt;br /&gt;
He just drained another 3mln and sold again for 13 $ETH. &lt;br /&gt;
&lt;br /&gt;
All the tokens have been drained from the contract. No more selling pressure.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Tapioca DAO has suffered a social engineering attack. This enabled the attacker to compromise the TAP token vesting contract’s ownership which allowed the attacker to claim and sell this 30M vested TAP, which impacted the TAP/ETH DAO owned LP. The attacker then also comprised the USDO stablecoin contract’s ownership and added a minter to infinite mint USDO and drain the USDO/USDC LP pair. In total, 591 ETH &amp;amp; 2.8M USDC were stolen.&lt;br /&gt;
&lt;br /&gt;
We have coordinated and are active in a war room with the necessary individuals and entities to proceed forward, and will be communicating on further steps when the situation is under control.&lt;br /&gt;
&lt;br /&gt;
Please be aware of misinformation, scam links, and do not interact with any Tapioca contracts or tokens until further information is provided.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;We have hacked the hacker! Recovered 1000 ETH which is now safely in the DAO multisig. The 1000 ETH was DAO collateral within Big Bang Origins to mint USDO for USDO/USDC LP.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
With this recovery, Tapioca's treasury now stands at $4.2M.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
The total amount recovered has been estimated at $4,200,000 USD.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
&amp;quot;Some funds have been recovered, though the full extent of the damage remains to be seen, though the full extent of the damage remains to be seen.&amp;quot;&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;rektnews-16187&amp;quot;&amp;gt;[https://rekt.news/tapioca-dao-rekt/ Rekt - Tapioca DAO - Rekt] (Accessed Oct 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;0xteuntwitter-16188&amp;quot;&amp;gt;[https://twitter.com/0xTeun/status/1847235350915145888 @0xTeun Twitter] (Accessed Oct 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;tapiocadaotwitter-16189&amp;quot;&amp;gt;[https://twitter.com/tapioca_dao/status/1847330264139145361 @tapioca_dao Twitter] (Accessed Oct 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;arbiscan-16190&amp;quot;&amp;gt;[https://arbiscan.io/tx/0x8cf8def40fa2beab66f46863478bea71ad8f4512003caf2fa639cc5a00550753 Arbitrum One Transaction Hash (Txhash) Details | Arbitrum One] (Accessed Oct 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;arbiscan-16191&amp;quot;&amp;gt;[https://arbiscan.io/tx/0x1abb8cf0b0af2ce19a30ce5103d51269d4600d9aeba045260feb588db89d76a4 Arbitrum One Transaction Hash (Txhash) Details | Arbitrum One] (Accessed Oct 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;arbiscan-16192&amp;quot;&amp;gt;[https://arbiscan.io/tx/0x174c3deaf563be1bb6d873ba279421e8588acc888ef672bafd5efe7441aae74f Arbitrum One Transaction Hash (Txhash) Details | Arbitrum One] (Accessed Oct 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;arbiscan-16193&amp;quot;&amp;gt;[https://arbiscan.io/tx/0x0bca43cfb5b14ea039f2b329cb6074383d54ed8240963014ccb6400befa5a4e3 Arbitrum One Transaction Hash (Txhash) Details | Arbitrum One] (Accessed Oct 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;zachxbttwitter-16194&amp;quot;&amp;gt;[https://twitter.com/zachxbt/status/1847249205720408138 @zachxbt Twitter] (Accessed Oct 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;officerciatwitter-16195&amp;quot;&amp;gt;[https://twitter.com/officer_cia/status/1847238678931759489 @officer_cia Twitter] (Accessed Oct 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coingecko-16196&amp;quot;&amp;gt;[https://www.coingecko.com/en/coins/tapioca-dao-token https://www.coingecko.com/en/coins/tapioca-dao-token] (Accessed Oct 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;tapioca-16197&amp;quot;&amp;gt;[https://www.tapioca.xyz/ Tapioca - The Omnichain Money Market] (Accessed Oct 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;tapiocadocs-16198&amp;quot;&amp;gt;[https://docs.tapioca.xyz/tapioca TapiocaDAO | TapiocaDAO] (Accessed Oct 21, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>