All public logs
Jump to navigation
Jump to search
Combined display of all available logs of Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository. You can narrow down the view by selecting a log type, the username (case-sensitive), or the affected page (also case-sensitive).
- 15:26, 27 January 2023 Azoundria talk contribs uploaded File:Zabufinance.jpg
- 15:26, 27 January 2023 Azoundria talk contribs created page Ledger Wallet Cleared Out TuckerCR (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/ledgerwalletclearedouttuckercr.php}} thumb|LedgerReddit user TuckerCR was tricked into divulging his seed phrase to a scammer on Telegram. He was directed to a website which appeared legitimate and allowed him to enter his seed phrase, after which his funds were immediately removed from the account. He reportedly lost $350k orth of BTC and ETH. This is a global/international c...")
- 15:26, 27 January 2023 Azoundria talk contribs created page AFK Finance Goes AFK (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/afkfinancegoesafk.php}} thumb|AFK Systems FinanceAs a completely anonymous team, AFK Systems Finance launched a new platform including a vault, with known exploits in the smart contract hot wallet. They then got a couple of smart contract auditors to audit the smart contract, presumably until they found one which wouldn't do the audit right away. When the audit results came...")
- 15:26, 27 January 2023 Azoundria talk contribs created page File:Afkfinance.jpg
- 15:26, 27 January 2023 Azoundria talk contribs uploaded File:Afkfinance.jpg
- 15:26, 27 January 2023 Azoundria talk contribs created page DYdX Pledge Contract Bug (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/dydxpledgecontractbug.php}} thumb|DYdXThe audited dYdX contract was launched with an incorrect ratio, which prevented users from performing withdrawals as anticipated. Funds were locked in the smart contract, and all are recoverable. This is a global/international case not involving a specific country. == About DYdX == "Perpetuals, decentralized." "Trade Perpetual Contracts wit...")
- 15:25, 27 January 2023 Azoundria talk contribs created page File:Dydx.jpg
- 15:25, 27 January 2023 Azoundria talk contribs uploaded File:Dydx.jpg
- 15:24, 27 January 2023 Azoundria talk contribs created page OpenZeppelin UUPS Proxy Initialization Vulnerability (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openzeppelinuupsproxyinitializationvulnerability.php}} thumb|OpenZeppelinThe OpenZeppelin smart contract framework had a vulnerability which would allow an adversary to take over the smart contract, if it hadn't been initialized yet. It's unclear if it was possible to take any funds using this method, however it was certainly possible to destroy existing smart contracts,...")
- 15:24, 27 January 2023 Azoundria talk contribs created page Convex Finance Malicious Search Results (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/convexfinancemalicioussearchresults.php}} thumb|Convex FinanceConvex Finance is a tool to increase rewards for stakers and liquidity providers on the curve protocol. Malicious entities made a copy of their website on a similar domain name, which most likely attempted to trick users into making payments or divulging their seed phrase. It is unclear if any funds were succe...")
- 15:24, 27 January 2023 Azoundria talk contribs created page File:Convexfinance.jpg
- 15:24, 27 January 2023 Azoundria talk contribs uploaded File:Convexfinance.jpg
- 15:24, 27 January 2023 Azoundria talk contribs created page DAO Maker Insufficient Authentication (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/daomakerinsufficientauthentication.php}} thumb|DAO MakerDAO Maker ran a service to enable other projects to launch coins and gain funding. All the token funds were stored in smart contract hot wallets, and the team decided that they didn't need to check who was calling the init function. A hacker decided they would like to initialize some of these wallets for themselves, and...")
- 15:24, 27 January 2023 Azoundria talk contribs created page Siren Market Reentrancy Bug (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/sirenmarketreentrancybug.php}} thumb|Siren MarketSiren Market is a decentralized protocol for options. The decision was made to store all funds in a smart contract hot wallet, based on the certainty of the audit by QuantStamp. However, this missed an exploit since it was in "an unusual spot". Therefore, all users face the loss of their funds unless the attacker returns t...")
- 15:24, 27 January 2023 Azoundria talk contribs created page File:Sirenprotocol.jpg
- 15:24, 27 January 2023 Azoundria talk contribs uploaded File:Sirenprotocol.jpg
- 15:23, 27 January 2023 Azoundria talk contribs created page CryptoShares Pyramid Scheme (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/cryptosharespyramidscheme.php}} thumb|CryptoSharesCryptoShares was a scheme run primarily from Zimbabwe by Martin Mhlanga. Investors were promised significant returns of $2000/mo, in exchange for an upfront payment of $330. No payments were ever received, and the founder disappeared on September 1st. It does not seem like anything will be made right for affected users. T...")
- 15:23, 27 January 2023 Azoundria talk contribs created page File:Cryptoshares.jpg
- 15:23, 27 January 2023 Azoundria talk contribs uploaded File:Cryptoshares.jpg
- 15:23, 27 January 2023 Azoundria talk contribs created page Banksy Fake NFT Sale on OpenSea (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/banksyfakenftsaleonopensea.php}} thumb|BanksyPranksy received an anonymous Discord message about a new NFT on the Banksy website, and placed the winning bid. No sooner had he done that then the NFT page was taken down and he found out the whole thing had been an elaborate fake. A hacker had hacked the banksy website, listed their NFT on OpenSea, and then promoted it extensivel...")
- 15:23, 27 January 2023 Azoundria talk contribs created page Cream Finance Reentrancy Bug (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/creamfinancereentrancybug.php}} thumb|Cream FinanceCream Finance is a decentralized lending program. There was a reentrancy exploit in the smart contract hot wallet where AMP and ETH were stored. This enabled a hacker to remove 462,079,976 in AMP and 2,804.96 ETH. It appears that Cream Finance has committed to making this right, and that the hacker ultimately returned the...")
- 15:22, 27 January 2023 Azoundria talk contribs created page Bilaxy Hot Wallet Breach (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/bilaxyhotwalletbreach.php}} thumb|BilaxyBilaxy is a cryptocurrency exchange platform based in Seychelles. On August 29th, 2021, their ERC20 hot wallet was breached. Other funds remained safe. The exchange ultimately reopened withdrawals a month later on September 23rd, however it's unclear if the affected ERC20 tokens will ever be available for users. This exchange or platform...")
- 15:22, 27 January 2023 Azoundria talk contribs created page File:Bilaxy.jpg
- 15:22, 27 January 2023 Azoundria talk contribs uploaded File:Bilaxy.jpg
- 15:22, 27 January 2023 Azoundria talk contribs created page XToken Function Access Control Exploit (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/xtokenfunctionaccesscontrolexploit.php}} thumb|XTokenxToken stored user funds in a particularly complex smart contract hot wallet. Through missing checks, an attacker was able to drain the wallet. xToken plans to compensate users, and retire the contract, which was already breached once in May. This is a global/international case not involving a specific country. == About XTo...")
- 15:22, 27 January 2023 Azoundria talk contribs created page OpenSea sohrobf Fake Support Scam (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openseasohrobffakesupportscam.php}} thumb|OpenSeaOpenSea is one of the largest markets for NFTs globally. One of the users with 11 NFTs was tricked by an opportunistic team of scammers who messaged him exactly at the same time he reached out for help to staff in the public Discord. The scammers looked nearly identical to the legitimate support staff. After a lengthy discussion...")
- 15:21, 27 January 2023 Azoundria talk contribs created page AB Finance Airdrop Scam (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/abfinanceairdropscam.php}} thumb|AB FinanceAt some point on August 25th of 2021, millions of Binance smart chain addresses received a mysterious ABFin token, which appeared to be valuable and directed them to abfin.org. On that website, AB Finance claimed to be a regulated company and that all users had to do to sell their tokens was to unlock them. The unlocking process onl...")
- 15:21, 27 January 2023 Azoundria talk contribs created page File:Abfinance.jpg
- 15:21, 27 January 2023 Azoundria talk contribs uploaded File:Abfinance.jpg
- 15:21, 27 January 2023 Azoundria talk contribs created page Dot Finance Minting Vulnerability (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/dotfinancemintingvulnerability.php}} thumb|Dot FinanceDot Finance offers an innovative yield farm. Despite two audits, their smart contract still suffered from a minting vulnerability. Their platform token dropped in value as the additional tokens were sold. There is no mention of the breach on their social media or website. It's unclear if anything was done to address it....")
- 15:21, 27 January 2023 Azoundria talk contribs created page File:Dotfinance.jpg
- 15:21, 27 January 2023 Azoundria talk contribs uploaded File:Dotfinance.jpg
- 15:20, 27 January 2023 Azoundria talk contribs created page Coinbase Vidovic Account Sim Swap (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/coinbasevidovicaccountsimswap.php}} thumb|CoinbaseCoinbase is the largest exchange platform in the United States. Cryptocurrency investors Tanja and Jared Vidovic had grown an investment to nearly $170k, and secured their accounts with SMS-based two-factor authentication. The attacker was able to trick their cell phone provider into switching the phone service to a new phone,...")
- 15:20, 27 January 2023 Azoundria talk contribs created page OpenSea Fake Support Accounts (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openseafakesupportaccounts.php}} thumb|OpenSeaOpenSea is one of the largest NFT marketplaces in the world. In August 2021, an OpenSea user fell for an advanced social engineering ploy where the scammers pretended to be an entire OpenSea support team with multiple idle staff on Discord. The end goal of the scam is to get the victim to display their QR code for syncing with Mobi...")
- 15:19, 27 January 2023 Azoundria talk contribs created page OpenZeppelin Timelock Reentrancy Vulnerability (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openzeppelintimelockreentrancyvulnerability.php}} thumb|OpenZeppelinIt was uncovered that OpenZeppelin, a well-known smart contract audit provider, had a critical vulnerability in their smart contract, which would have allowed privilege escallation. This was found through a bug bounty program, and not exploited, so no funds were lost. A significant number of projects all...")
- 15:19, 27 January 2023 Azoundria talk contribs created page File:Openzeppelin.jpg
- 15:19, 27 January 2023 Azoundria talk contribs uploaded File:Openzeppelin.jpg
- 15:19, 27 January 2023 Azoundria talk contribs created page Luna Yield Rug Pull (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/lunayieldrugpull.php}} thumb|Luna YieldLuna Yield was another yield optimizing service, where users provided liquidity in a smart contract hot wallet. After the smart contract was exploited, the anonymous team provided affected users 60% of their invested USDC back. Social media accounts were also deleted. This is a global/international case not involving a specific country...")
- 15:19, 27 January 2023 Azoundria talk contribs created page File:Lunayield.jpg
- 15:19, 27 January 2023 Azoundria talk contribs uploaded File:Lunayield.jpg
- 15:18, 27 January 2023 Azoundria talk contribs created page Solend Insecure Authentication Check (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/solendinsecureauthenticationcheck.php}} thumb|SolendSolend is a lending protocol for Solana. The smart contract hot wallets had a vulnerability which allowed an attacker to escalate their permissions and change configuration parameters in a new lending market. This would have allowed them to steal the funds of users on a much larger scale. Luckily, the issue was detected early,...")
- 15:18, 27 January 2023 Azoundria talk contribs created page File:Solend.jpg
- 15:18, 27 January 2023 Azoundria talk contribs uploaded File:Solend.jpg
- 15:18, 27 January 2023 Azoundria talk contribs created page BSCToken Scam Website (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/bsctokenscamwebsite.php}} thumb|BSCTokenThe BSCToken website is a phishing site designed to trick users to give access to their wallet, where funds will be withdrawn. This is a global/international case not involving a specific country. == About BSCToken == "Leveraged yield farming with the BSCTOKEN. BSC Token Finance is a regulated Company. All you need to do in order to e...")
- 15:18, 27 January 2023 Azoundria talk contribs created page File:Bsctoken.jpg
- 15:18, 27 January 2023 Azoundria talk contribs uploaded File:Bsctoken.jpg
- 15:17, 27 January 2023 Azoundria talk contribs created page Liquid Warm Wallet Liquidated (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/liquidwarmwalletliquidated.php}} thumb|LiquidLiquid is one of the largest exchanges globally. Hackers were able to access their warm wallets and complete the withdrawal of all assets, most likely by simply requesting a series of withdrawals once they gained access to the system. Despite using multi-sig, all of the factors evidently were breached by the single hacker, and likely...")
- 15:17, 27 January 2023 Azoundria talk contribs created page Pinecone Finance Deflation Hack (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/pineconefinancedeflationhack.php}} thumb|Pinecone FinancePinecone Finance offers a new yield farm for staking, where users deposit their funds into a smart contract hot wallet, earning profit by providing market liquidity. There was an exploit which was possible with deflationary tokens, where a hacker was able to gain $200k. The hacker returned the funds in a subsequ...")
- 15:17, 27 January 2023 Azoundria talk contribs created page File:Pineconefinance.jpg
- 15:17, 27 January 2023 Azoundria talk contribs uploaded File:Pineconefinance.jpg