All public logs
Jump to navigation
Jump to search
Combined display of all available logs of Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository. You can narrow down the view by selecting a log type, the username (case-sensitive), or the affected page (also case-sensitive).
- 15:23, 27 January 2023 Azoundria talk contribs created page File:Cryptoshares.jpg
- 15:23, 27 January 2023 Azoundria talk contribs uploaded File:Cryptoshares.jpg
- 15:23, 27 January 2023 Azoundria talk contribs created page Banksy Fake NFT Sale on OpenSea (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/banksyfakenftsaleonopensea.php}} thumb|BanksyPranksy received an anonymous Discord message about a new NFT on the Banksy website, and placed the winning bid. No sooner had he done that then the NFT page was taken down and he found out the whole thing had been an elaborate fake. A hacker had hacked the banksy website, listed their NFT on OpenSea, and then promoted it extensivel...")
- 15:23, 27 January 2023 Azoundria talk contribs created page Cream Finance Reentrancy Bug (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/creamfinancereentrancybug.php}} thumb|Cream FinanceCream Finance is a decentralized lending program. There was a reentrancy exploit in the smart contract hot wallet where AMP and ETH were stored. This enabled a hacker to remove 462,079,976 in AMP and 2,804.96 ETH. It appears that Cream Finance has committed to making this right, and that the hacker ultimately returned the...")
- 15:22, 27 January 2023 Azoundria talk contribs created page Bilaxy Hot Wallet Breach (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/bilaxyhotwalletbreach.php}} thumb|BilaxyBilaxy is a cryptocurrency exchange platform based in Seychelles. On August 29th, 2021, their ERC20 hot wallet was breached. Other funds remained safe. The exchange ultimately reopened withdrawals a month later on September 23rd, however it's unclear if the affected ERC20 tokens will ever be available for users. This exchange or platform...")
- 15:22, 27 January 2023 Azoundria talk contribs created page File:Bilaxy.jpg
- 15:22, 27 January 2023 Azoundria talk contribs uploaded File:Bilaxy.jpg
- 15:22, 27 January 2023 Azoundria talk contribs created page XToken Function Access Control Exploit (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/xtokenfunctionaccesscontrolexploit.php}} thumb|XTokenxToken stored user funds in a particularly complex smart contract hot wallet. Through missing checks, an attacker was able to drain the wallet. xToken plans to compensate users, and retire the contract, which was already breached once in May. This is a global/international case not involving a specific country. == About XTo...")
- 15:22, 27 January 2023 Azoundria talk contribs created page OpenSea sohrobf Fake Support Scam (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openseasohrobffakesupportscam.php}} thumb|OpenSeaOpenSea is one of the largest markets for NFTs globally. One of the users with 11 NFTs was tricked by an opportunistic team of scammers who messaged him exactly at the same time he reached out for help to staff in the public Discord. The scammers looked nearly identical to the legitimate support staff. After a lengthy discussion...")
- 15:21, 27 January 2023 Azoundria talk contribs created page AB Finance Airdrop Scam (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/abfinanceairdropscam.php}} thumb|AB FinanceAt some point on August 25th of 2021, millions of Binance smart chain addresses received a mysterious ABFin token, which appeared to be valuable and directed them to abfin.org. On that website, AB Finance claimed to be a regulated company and that all users had to do to sell their tokens was to unlock them. The unlocking process onl...")
- 15:21, 27 January 2023 Azoundria talk contribs created page File:Abfinance.jpg
- 15:21, 27 January 2023 Azoundria talk contribs uploaded File:Abfinance.jpg
- 15:21, 27 January 2023 Azoundria talk contribs created page Dot Finance Minting Vulnerability (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/dotfinancemintingvulnerability.php}} thumb|Dot FinanceDot Finance offers an innovative yield farm. Despite two audits, their smart contract still suffered from a minting vulnerability. Their platform token dropped in value as the additional tokens were sold. There is no mention of the breach on their social media or website. It's unclear if anything was done to address it....")
- 15:21, 27 January 2023 Azoundria talk contribs created page File:Dotfinance.jpg
- 15:21, 27 January 2023 Azoundria talk contribs uploaded File:Dotfinance.jpg
- 15:20, 27 January 2023 Azoundria talk contribs created page Coinbase Vidovic Account Sim Swap (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/coinbasevidovicaccountsimswap.php}} thumb|CoinbaseCoinbase is the largest exchange platform in the United States. Cryptocurrency investors Tanja and Jared Vidovic had grown an investment to nearly $170k, and secured their accounts with SMS-based two-factor authentication. The attacker was able to trick their cell phone provider into switching the phone service to a new phone,...")
- 15:20, 27 January 2023 Azoundria talk contribs created page OpenSea Fake Support Accounts (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openseafakesupportaccounts.php}} thumb|OpenSeaOpenSea is one of the largest NFT marketplaces in the world. In August 2021, an OpenSea user fell for an advanced social engineering ploy where the scammers pretended to be an entire OpenSea support team with multiple idle staff on Discord. The end goal of the scam is to get the victim to display their QR code for syncing with Mobi...")
- 15:19, 27 January 2023 Azoundria talk contribs created page OpenZeppelin Timelock Reentrancy Vulnerability (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openzeppelintimelockreentrancyvulnerability.php}} thumb|OpenZeppelinIt was uncovered that OpenZeppelin, a well-known smart contract audit provider, had a critical vulnerability in their smart contract, which would have allowed privilege escallation. This was found through a bug bounty program, and not exploited, so no funds were lost. A significant number of projects all...")
- 15:19, 27 January 2023 Azoundria talk contribs created page File:Openzeppelin.jpg
- 15:19, 27 January 2023 Azoundria talk contribs uploaded File:Openzeppelin.jpg
- 15:19, 27 January 2023 Azoundria talk contribs created page Luna Yield Rug Pull (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/lunayieldrugpull.php}} thumb|Luna YieldLuna Yield was another yield optimizing service, where users provided liquidity in a smart contract hot wallet. After the smart contract was exploited, the anonymous team provided affected users 60% of their invested USDC back. Social media accounts were also deleted. This is a global/international case not involving a specific country...")
- 15:19, 27 January 2023 Azoundria talk contribs created page File:Lunayield.jpg
- 15:19, 27 January 2023 Azoundria talk contribs uploaded File:Lunayield.jpg
- 15:18, 27 January 2023 Azoundria talk contribs created page Solend Insecure Authentication Check (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/solendinsecureauthenticationcheck.php}} thumb|SolendSolend is a lending protocol for Solana. The smart contract hot wallets had a vulnerability which allowed an attacker to escalate their permissions and change configuration parameters in a new lending market. This would have allowed them to steal the funds of users on a much larger scale. Luckily, the issue was detected early,...")
- 15:18, 27 January 2023 Azoundria talk contribs created page File:Solend.jpg
- 15:18, 27 January 2023 Azoundria talk contribs uploaded File:Solend.jpg
- 15:18, 27 January 2023 Azoundria talk contribs created page BSCToken Scam Website (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/bsctokenscamwebsite.php}} thumb|BSCTokenThe BSCToken website is a phishing site designed to trick users to give access to their wallet, where funds will be withdrawn. This is a global/international case not involving a specific country. == About BSCToken == "Leveraged yield farming with the BSCTOKEN. BSC Token Finance is a regulated Company. All you need to do in order to e...")
- 15:18, 27 January 2023 Azoundria talk contribs created page File:Bsctoken.jpg
- 15:18, 27 January 2023 Azoundria talk contribs uploaded File:Bsctoken.jpg
- 15:17, 27 January 2023 Azoundria talk contribs created page Liquid Warm Wallet Liquidated (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/liquidwarmwalletliquidated.php}} thumb|LiquidLiquid is one of the largest exchanges globally. Hackers were able to access their warm wallets and complete the withdrawal of all assets, most likely by simply requesting a series of withdrawals once they gained access to the system. Despite using multi-sig, all of the factors evidently were breached by the single hacker, and likely...")
- 15:17, 27 January 2023 Azoundria talk contribs created page Pinecone Finance Deflation Hack (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/pineconefinancedeflationhack.php}} thumb|Pinecone FinancePinecone Finance offers a new yield farm for staking, where users deposit their funds into a smart contract hot wallet, earning profit by providing market liquidity. There was an exploit which was possible with deflationary tokens, where a hacker was able to gain $200k. The hacker returned the funds in a subsequ...")
- 15:17, 27 January 2023 Azoundria talk contribs created page File:Pineconefinance.jpg
- 15:17, 27 January 2023 Azoundria talk contribs uploaded File:Pineconefinance.jpg
- 15:16, 27 January 2023 Azoundria talk contribs created page SushiSwap MISO White Hat Diffusal (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/sushiswapmisowhitehatdiffusal.php}} thumb|SushiSwapThe SushiSwap MISO is a smart contract which assists with launching new coins and tokens which are managed through a smart contract hot wallet. The contract underwent 3 separate audits by reputable firms as well as multiple security researchers had reviewed it. And yet, there was still a bug found which would have been able...")
- 15:16, 27 January 2023 Azoundria talk contribs created page XSurge Reentrancy Attack (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/xsurgereentrancyattack.php}} thumb|XSurgeThe XSurge smart contract was exploited and $5m was taken from investors. It appears that XSurge is making efforts to recompensate affected users. They put out an initial snapshot of balances to be compensated. They also completed an audit with CertiK. This is a global/international case not involving a specific country. == About XSur...")
- 15:16, 27 January 2023 Azoundria talk contribs created page File:Xsurge.jpg
- 15:16, 27 January 2023 Azoundria talk contribs uploaded File:Xsurge.jpg
- 15:15, 27 January 2023 Azoundria talk contribs created page Curve Bribe Exploit (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/curvebribeexploit.php}} thumb|Curve FinanceThe Curve Bribe utility allows bribing Curve holders to vote a certain way in the decentralized governance protocol. The assets were stored in a smart contract hot wallet, and this was breachable. A white hack was performed to extract the funds, which were put in a new contract. This is a global/international case not involving...")
- 15:15, 27 January 2023 Azoundria talk contribs created page Ref Finance Logic Error (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/reffinancelogicerror.php}} thumb|Ref FinanceRef Finance offers a variety of products and services on the NEAR protocol. After releasing a "hotfix" to their protocol, a vulnerability was introduced which allowed for the theft of a significant amount of NEAR and REF tokens from their smart contract hot wallet. The REF token was forked to eliminate the stolen tokens, and the N...")
- 15:15, 27 January 2023 Azoundria talk contribs created page File:Reffinance.jpg
- 15:15, 27 January 2023 Azoundria talk contribs uploaded File:Reffinance.jpg
- 15:15, 27 January 2023 Azoundria talk contribs created page Pixel-Track Hex Tokens Stolen (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/pixeltrackhextokensstolen.php}} thumb|MetaMaskReddit user Pixel-Track introduces themselves as someone from an older generation who is not experienced with cryptocurrency. They reported that they did not share their seed phrase or private key with anyone, however they were attempting to stake their HEX tokens and this was not successful. They report that their funds were take...")
- 15:14, 27 January 2023 Azoundria talk contribs created page Dao Maker Exploit (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/daomakerexploit.php}} thumb|Dao MakerDAO Maker offers a comprehensive suite of DeFi products. One of the admin keys was exploited, in order to steal the funds of users stored in the platform. Ultimately, the team came up with a recovery plan for all affected users, and also restructured the smart contract such that no funds were under their custody, eliminating the centraliz...")
- 15:14, 27 January 2023 Azoundria talk contribs created page File:Daomaker.jpg
- 15:14, 27 January 2023 Azoundria talk contribs uploaded File:Daomaker.jpg
- 15:14, 27 January 2023 Azoundria talk contribs created page Shazbot /Yoda NFT Wallet Compromised (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/shazbotyodanftwalletcompromised.php}} thumb|MetaMaskAn NFT collector who goes by the name Yoda was tricked into revealing their private key seed phrase via a discord scam. While they didn't click "Next", the key was still entered into a live website. A significant quantity of NFTs were taken, however this was less than half of the NFTs present in their account at the time. Th...")
- 15:14, 27 January 2023 Azoundria talk contribs created page Poly Network Validation Error (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/polynetworkvalidationerror.php}} thumb|Poly NetworkThe Poly Network allows different smart chains to interact with one another securely. However, it contained a vulnerability which allowed funds to be removed. A hacker exploited the vulnerability, messed up their transactions such that their identity became known, and then proceeded to return the funds in exchange for a $5...")
- 15:13, 27 January 2023 Azoundria talk contribs created page File:Polynetwork.jpg
- 15:13, 27 January 2023 Azoundria talk contribs uploaded File:Polynetwork.jpg
- 15:13, 27 January 2023 Azoundria talk contribs created page Punk Protocol Reinitialized (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/punkprotocolreinitialized.php}} thumb|Punk ProtocolThe Punk Protocol is a decentralized annuity protocol, which allows investors to contribute and pays out periodic regular cash flows. All funds were stored in a smart contract hot wallet. A malicious hacker found an exploit, allowing them to reinitialize the smart contract hot wallet. However, while their transaction sat...")