8ight Finance Private Key Leak: Difference between revisions

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search
(Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/8ightfinanceprivatekeyleak.php}} thumb|8ight Finance8ight Finance was launching an 8-ball themed DAO on the Harmony blockchain. According to the official story, the private key was shared through Google Docs and Facebook, and either of the two admins had access to it. All $1.75m was taken from the treasury. The team offered to disburse $250k of marketing budget or relaunc...")
 
No edit summary
Line 1: Line 1:
{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/8ightfinanceprivatekeyleak.php}}
{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/8ightfinanceprivatekeyleak.php}}
{{Unattributed Sources}}


[[File:8ightfinance.jpg|thumb|8ight Finance]]8ight Finance was launching an 8-ball themed DAO on the Harmony blockchain. According to the official story, the private key was shared through Google Docs and Facebook, and either of the two admins had access to it. All $1.75m was taken from the treasury. The team offered to disburse $250k of marketing budget or relaunch a new protocol, and the community voted for a relaunch. Presently, there do not appear to be any updates and the website is offline, though Twitter and Medium are still available.
[[File:8ightfinance.jpg|thumb|8ight Finance]]8ight Finance was launching an 8-ball themed DAO on the Harmony blockchain. According to the official story, the private key was shared through Google Docs and Facebook, and either of the two admins had access to it. All $1.75m was taken from the treasury. The team offered to disburse $250k of marketing budget or relaunch a new protocol, and the community voted for a relaunch. Presently, there do not appear to be any updates and the website is offline, though Twitter and Medium are still available.


This is a global/international case not involving a specific country.
This is a global/international case not involving a specific country.
<ref name="rektnews-5232" /><ref name="coinmarketcap-5233" /><ref name="8ightfinancetwitter-5234" /><ref name="8ightfinancetwitter-5235" /><ref name="explorer-5236" /><ref name="explorer-5237" /><ref name="explorer-5238" /><ref name="explorer-5239" /><ref name="8ightfinancearchive-5240" /><ref name="eightdaomedium-5241" /><ref name="eightdaomedium-5242" /><ref name="eightdaomedium-5243" /><ref name="eightdaomedium-5244" /><ref name="eightdaomedium-5245" /><ref name="etherscan-5246" /><ref name="youtube-5247" /><ref name="coincodecapblog-5248" /><ref name="isthiscoinascam-5249" /><ref name="fullycrypto-5250" /><ref name="aliens-5251" />


== About 8ight Finance ==
== About 8ight Finance ==
Line 112: Line 114:


== References ==
== References ==
[https://rekt.news/8ight-finance-rekt/ https://rekt.news/8ight-finance-rekt/] (Jan 3)
<references><ref name="rektnews-5232">[https://rekt.news/8ight-finance-rekt/ https://rekt.news/8ight-finance-rekt/] (Jan 3, 2022)</ref>


[https://coinmarketcap.com/currencies/8ight-finance/ https://coinmarketcap.com/currencies/8ight-finance/] (Jan 4)
<ref name="coinmarketcap-5233">[https://coinmarketcap.com/currencies/8ight-finance/ https://coinmarketcap.com/currencies/8ight-finance/] (Jan 4, 2022)</ref>


[https://twitter.com/8ight_finance/status/1468073179784486912 @8ight_finance Twitter] (Jan 4)
<ref name="8ightfinancetwitter-5234">[https://twitter.com/8ight_finance/status/1468073179784486912 @8ight_finance Twitter] (Jan 4, 2022)</ref>


[https://twitter.com/8ight_finance/status/1467897012553019394 @8ight_finance Twitter] (Jan 4)
<ref name="8ightfinancetwitter-5235">[https://twitter.com/8ight_finance/status/1467897012553019394 @8ight_finance Twitter] (Jan 4, 2022)</ref>


[https://explorer.harmony.one/tx/0x7a9aeca34468a667fd1cc045d12245b424fcaf65ab97c54cb09ac0f48b9af964 Harmony Blockchain Explorer] (Jan 4)
<ref name="explorer-5236">[https://explorer.harmony.one/tx/0x7a9aeca34468a667fd1cc045d12245b424fcaf65ab97c54cb09ac0f48b9af964 Harmony Blockchain Explorer] (Jan 4, 2022)</ref>


[https://explorer.harmony.one/tx/0x0af0e8ea2af54429ba84f1e645725b6c6b0844fccc7fa4e2f69dc580a2dc70b2 Harmony Blockchain Explorer] (Jan 4)
<ref name="explorer-5237">[https://explorer.harmony.one/tx/0x0af0e8ea2af54429ba84f1e645725b6c6b0844fccc7fa4e2f69dc580a2dc70b2 Harmony Blockchain Explorer] (Jan 4, 2022)</ref>


[https://explorer.harmony.one/tx/0x71a8fa404b7d8b4776397dedb5c7aa9090e045d86a8c621ae1b681fb92ec5bf9 Harmony Blockchain Explorer] (Jan 4)
<ref name="explorer-5238">[https://explorer.harmony.one/tx/0x71a8fa404b7d8b4776397dedb5c7aa9090e045d86a8c621ae1b681fb92ec5bf9 Harmony Blockchain Explorer] (Jan 4, 2022)</ref>


[https://explorer.harmony.one/tx/0xbe7617d4c46c334327a018d6cfe7d6d492726b102f2d63d57da5ee11ab797bec Harmony Blockchain Explorer] (Jan 4)
<ref name="explorer-5239">[https://explorer.harmony.one/tx/0xbe7617d4c46c334327a018d6cfe7d6d492726b102f2d63d57da5ee11ab797bec Harmony Blockchain Explorer] (Jan 4, 2022)</ref>


[https://web.archive.org/web/20211027231505/https://8ight.finance/ 8ight DAO | The Decentralized Reserve Currency] (Jan 4)
<ref name="8ightfinancearchive-5240">[https://web.archive.org/web/20211027231505/https://8ight.finance/ 8ight DAO | The Decentralized Reserve Currency] (Jan 4, 2022)</ref>


[https://medium.com/@eightdao/introducing-8ight-finance-a-decentralized-reservation-currency-protocol-3b902ce206a7 https://medium.com/@eightdao/introducing-8ight-finance-a-decentralized-reservation-currency-protocol-3b902ce206a7] (Jan 4)
<ref name="eightdaomedium-5241">[https://medium.com/@eightdao/introducing-8ight-finance-a-decentralized-reservation-currency-protocol-3b902ce206a7 https://medium.com/@eightdao/introducing-8ight-finance-a-decentralized-reservation-currency-protocol-3b902ce206a7] (Jan 4, 2022)</ref>


[https://medium.com/@eightdao/incident-report-future-plans-ad51c65c66e7 https://medium.com/@eightdao/incident-report-future-plans-ad51c65c66e7] (Jan 4)
<ref name="eightdaomedium-5242">[https://medium.com/@eightdao/incident-report-future-plans-ad51c65c66e7 https://medium.com/@eightdao/incident-report-future-plans-ad51c65c66e7] (Jan 4, 2022)</ref>


[https://medium.com/@eightdao/8ight-finance-dev-update-2-97b4afcbd78c https://medium.com/@eightdao/8ight-finance-dev-update-2-97b4afcbd78c] (Jan 4)
<ref name="eightdaomedium-5243">[https://medium.com/@eightdao/8ight-finance-dev-update-2-97b4afcbd78c https://medium.com/@eightdao/8ight-finance-dev-update-2-97b4afcbd78c] (Jan 4, 2022)</ref>


[https://medium.com/@eightdao/welcome-to-the-eight-ignition-phase-d78438577f19 https://medium.com/@eightdao/welcome-to-the-eight-ignition-phase-d78438577f19] (Jan 4)
<ref name="eightdaomedium-5244">[https://medium.com/@eightdao/welcome-to-the-eight-ignition-phase-d78438577f19 https://medium.com/@eightdao/welcome-to-the-eight-ignition-phase-d78438577f19] (Jan 4, 2022)</ref>


[https://medium.com/@eightdao/8ight-strategy-planning-d64ffe238356 https://medium.com/@eightdao/8ight-strategy-planning-d64ffe238356] (Jan 4)
<ref name="eightdaomedium-5245">[https://medium.com/@eightdao/8ight-strategy-planning-d64ffe238356 https://medium.com/@eightdao/8ight-strategy-planning-d64ffe238356] (Jan 4, 2022)</ref>


[https://etherscan.io/address/0x4d8071452bF5f629eA1c72E1e42A18aebc04cA1d Address 0x4d8071452bF5f629eA1c72E1e42A18aebc04cA1d | Etherscan] (Jan 4)
<ref name="etherscan-5246">[https://etherscan.io/address/0x4d8071452bF5f629eA1c72E1e42A18aebc04cA1d Address 0x4d8071452bF5f629eA1c72E1e42A18aebc04cA1d | Etherscan] (Jan 4, 2022)</ref>


[https://www.youtube.com/watch?v=R-5fQF4eNSk 8ight Finance SCAM ALERT? Only For Those Who Don't Believe. - YouTube] (Jan 4)
<ref name="youtube-5247">[https://www.youtube.com/watch?v=R-5fQF4eNSk 8ight Finance SCAM ALERT? Only For Those Who Don't Believe. - YouTube] (Jan 4, 2022)</ref>


[https://blog.coincodecap.com/8ight-finance-hacked-all-funds-in-treasury-withdrawn-due-to-leak-of-the-private-key 8ight Finance Hacked: All Funds in Treasury Withdrawn due to Leak of the Private Key | CoinCodeCap] (Jan 4)
<ref name="coincodecapblog-5248">[https://blog.coincodecap.com/8ight-finance-hacked-all-funds-in-treasury-withdrawn-due-to-leak-of-the-private-key 8ight Finance Hacked: All Funds in Treasury Withdrawn due to Leak of the Private Key | CoinCodeCap] (Jan 4, 2022)</ref>


[https://isthiscoinascam.com/check/8ight-finance Is 8ight Finance A Scam? Or Is 8ight Finance Legit?] (Jan 4)
<ref name="isthiscoinascam-5249">[https://isthiscoinascam.com/check/8ight-finance Is 8ight Finance A Scam? Or Is 8ight Finance Legit?] (Jan 4, 2022)</ref>


[https://fullycrypto.com/8ight-finance-admits-opsec-was-low-after-treasury-compromised 8ight Finance Admits "Opsec Was Low" After Treasury Compromised] (Jan 4)
<ref name="fullycrypto-5250">[https://fullycrypto.com/8ight-finance-admits-opsec-was-low-after-treasury-compromised 8ight Finance Admits "Opsec Was Low" After Treasury Compromised] (Jan 4, 2022)</ref>


[https://www.aliens.com/livenews/latest/8ight-finance-private-key-leaked-funds-were-transferred-out-and-sent-to-tornado-cash 8ight Finance private key leaked, funds were transferred out and sent to Tornado Cash - Aliens: AI Crypto News & Markets Updates] (Jan 4)
<ref name="aliens-5251">[https://www.aliens.com/livenews/latest/8ight-finance-private-key-leaked-funds-were-transferred-out-and-sent-to-tornado-cash 8ight Finance private key leaked, funds were transferred out and sent to Tornado Cash - Aliens: AI Crypto News & Markets Updates] (Jan 4, 2022)</ref></references>

Revision as of 11:48, 28 February 2023

Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' section to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!

8ight Finance

8ight Finance was launching an 8-ball themed DAO on the Harmony blockchain. According to the official story, the private key was shared through Google Docs and Facebook, and either of the two admins had access to it. All $1.75m was taken from the treasury. The team offered to disburse $250k of marketing budget or relaunch a new protocol, and the community voted for a relaunch. Presently, there do not appear to be any updates and the website is offline, though Twitter and Medium are still available.

This is a global/international case not involving a specific country. [1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17][18][19][20]

About 8ight Finance

"Fork of $OHM on $ONE." "8ight Finance is a Decentralized Autonomous Organization (DAO), built by experienced DeFi developers, designers, and researchers." "We are proud to be a part of Defi 2.0."

"8ight Finance is a Decentralized Autonomous Organization (DAO), built by experienced DeFi developers, designers, and researchers. Our goal is to fulfill @danielesesta’s promise that he can’t keep, and also to create a policy-controlled reserve currency system, in which the behavior of the $EIGHT token is controlled by the DAO. Let’s dive into the tokenomics of $EIGHT."

"OlympusDAO, Wonderland.money, KlimaDAO has introduced new tokenomics to the crypto world and has achieved great success over the past year. 8ight Finance is focusing on reducing and maintaining a super fast and cheap protocol’s operation fee which will yield even more in APY for stakers, henceforth more incentives for treasury growth."

"Our 8ight universe will be on the Harmony blockchain. We believe Harmony as an Ethereum scaling solution is the future of DeFi! It is worth mentioning that significant liquidity and a potential growing DeFi ecosystem already exist on Harmony, which should be a strong base for our system."

"Our long-term goal is to be seen as the decentralized reserve currency of Harmony and the broader DeFi ecosystem, an ecosystem we believe is primed for explosive growth." "8ight Finance guarantees to share 33% of the DAO profits to OlympusDAO."

"When $EIGHT market price is below 1 DAI, the protocol buys it back and burns $EIGHT. When $EIGHT market price is above 1 DAI, the protocol mints and sells new $EIGHT."

"This is because the treasury must hold 1 DAI and only 1 DAI for each $EIGHT. Every time the protocol is bought or sold, it makes a profit. That means the protocol either gets more than 1 DAI on the sale side or spends less than 1 DAI on the purchase side."

"The fact that the protocol holds DAI for each token allows us to say with certainty that $EIGHT will not trade below its intrinsic value in the long term."

"Building a solid protocol is hard work, and it requires capital. Audits, development, legal, all of these things need some amount of money to get done. Beyond that, it requires alignment so that contributors feel personally incentivized to give their all."

"The first 1,000 initial discord offering whitelist will be opened on the 30th of October. Everyone can get more entries in the whitelisting program by joining our Discord’s role tasks! The more entries you get, the more likely you will be on the whitelist!"

"We’ve successfully launched and we’re overwhelmed with the support that the community gave us. But no time for rest, our team return to work with the aim of bringing the community the best products"

On December 6th, "Our private key got compromised and the funds have been transferred out of the treasury." "First of all, we are dreadfully sorry for the incident." "8ight Finance, an OHM fork on Harmony that offered to help people affected by the Snowdog DAO rug pull, lost around $1.75 Million in what’s supposedly a private key leak."

“Two devs in the team have the key, and they were sent through Facebook groups chat and google drive. This is our first project, so we must admit our opsec was low. At the time when the withdrawal happened, our team was working on launching the BUSD (4,4) bonds. To be transparent with everyone, we lost a lot of money and time invested in 8ight, and it f*cking hurts to see someone else taking away everything we had built. We delivered everything on time, and we reached out to Harmony, DFK, and a lot of partnerships to try and grow EIGHT. You guys here all know the admin and the mods team worked our a*ses off, but the timing of the market, the downfall of SB and SDOG, OHM bond funds f*cked up the price action, and we tried our best to push and deliver. So our team will take in opinions and decide later on.”

"We had contacted Synapse to find where the money was transferred, and they provided us with this ETH address: 0x4d8071452bF5f629eA1c72E1e42A18aebc04cA1d"

"The money has been sent to Tornado Cash, which is currently untraceable. We are finding the solution to recover from this incident."

"The admins of the discord server have assured the investors and members who lost their funds that they wouldn’t go this far to rug the pool. However, since all the money has already been sent to Tornado Cash, it’ll be tough to identify who was actually behind the address used to transfer the funds."

"After the incident, we had conducted the community vote. As proposed by the community, the fund will be used to rebuild a new protocol."

"Our new detail identity is being completed due to the opinions and feedback from the community. Specifically, the new project will establish a multisig from the very start. (multisig is a committee that includes 4 key holders: 2 team members, and 2 mods from the community)."

"Every proposal would need consensus from at least 3/4 key holders, before being executed. Simply put, it will take us about 2.5–3 months to complete all the necessary steps to prepare and roll out the new project’s release."

This is a global/international case not involving a specific country.

The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.

Include:

  • Known history of when and how the service was started.
  • What problems does the company or service claim to solve?
  • What marketing materials were used by the firm or business?
  • Audits performed, and excerpts that may have been included.
  • Business registration documents shown (fake or legitimate).
  • How were people recruited to participate?
  • Public warnings and announcements prior to the event.

Don't Include:

  • Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
  • Anything that wasn't reasonably knowable at the time of the event.

There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.

The Reality

This sections is included if a case involved deception or information that was unknown at the time. Examples include:

  • When the service was actually started (if different than the "official story").
  • Who actually ran a service and their own personal history.
  • How the service was structured behind the scenes. (For example, there was no "trading bot".)
  • Details of what audits reported and how vulnerabilities were missed during auditing.

What Happened

The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.

Key Event Timeline - 8ight Finance Private Key Leak
Date Event Description
December 6th, 2021 12:00:00 AM Main Event Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here.

Total Amount Lost

The total amount lost has been estimated at $1,750,000 USD.

How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?

Immediate Reactions

How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?

Ultimate Outcome

What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?

Total Amount Recovered

There do not appear to have been any funds recovered in this case.

What funds were recovered? What funds were reimbursed for those affected users?

Ongoing Developments

What parts of this case are still remaining to be concluded?

Prevention Policies

It's important that all private keys be maintained offline and that a multi-sig be set up for any project with a treasury. Our framework outlines that key holders should be trained and that there should be two reviews of the setup when the project is ready to launch.

References

  1. https://rekt.news/8ight-finance-rekt/ (Jan 3, 2022)
  2. https://coinmarketcap.com/currencies/8ight-finance/ (Jan 4, 2022)
  3. @8ight_finance Twitter (Jan 4, 2022)
  4. @8ight_finance Twitter (Jan 4, 2022)
  5. Harmony Blockchain Explorer (Jan 4, 2022)
  6. Harmony Blockchain Explorer (Jan 4, 2022)
  7. Harmony Blockchain Explorer (Jan 4, 2022)
  8. Harmony Blockchain Explorer (Jan 4, 2022)
  9. 8ight DAO | The Decentralized Reserve Currency (Jan 4, 2022)
  10. https://medium.com/@eightdao/introducing-8ight-finance-a-decentralized-reservation-currency-protocol-3b902ce206a7 (Jan 4, 2022)
  11. https://medium.com/@eightdao/incident-report-future-plans-ad51c65c66e7 (Jan 4, 2022)
  12. https://medium.com/@eightdao/8ight-finance-dev-update-2-97b4afcbd78c (Jan 4, 2022)
  13. https://medium.com/@eightdao/welcome-to-the-eight-ignition-phase-d78438577f19 (Jan 4, 2022)
  14. https://medium.com/@eightdao/8ight-strategy-planning-d64ffe238356 (Jan 4, 2022)
  15. Address 0x4d8071452bF5f629eA1c72E1e42A18aebc04cA1d | Etherscan (Jan 4, 2022)
  16. 8ight Finance SCAM ALERT? Only For Those Who Don't Believe. - YouTube (Jan 4, 2022)
  17. 8ight Finance Hacked: All Funds in Treasury Withdrawn due to Leak of the Private Key | CoinCodeCap (Jan 4, 2022)
  18. Is 8ight Finance A Scam? Or Is 8ight Finance Legit? (Jan 4, 2022)
  19. 8ight Finance Admits "Opsec Was Low" After Treasury Compromised (Jan 4, 2022)
  20. 8ight Finance private key leaked, funds were transferred out and sent to Tornado Cash - Aliens: AI Crypto News & Markets Updates (Jan 4, 2022)