All public logs
Jump to navigation
Jump to search
Combined display of all available logs of Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository. You can narrow down the view by selecting a log type, the username (case-sensitive), or the affected page (also case-sensitive).
- 21:45, 27 January 2023 Azoundria talk contribs created page Baller Ape Club Rug Pull (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/ballerapeclubrugpull.php}} thumb|Baller Ape ClubBaller Ape Club was an NFT project that promised to launch on October 1st, 2021. They claimed 5,000 unique assets along with significant perks would be included. Through a clever twist, they tricked users into submitting their payments multiple times by claiming that each payment had failed to go through, and gave users mul...")
- 21:45, 27 January 2023 Azoundria talk contribs created page File:Ballerapeclub.jpg
- 21:45, 27 January 2023 Azoundria talk contribs uploaded File:Ballerapeclub.jpg
- 21:45, 27 January 2023 Azoundria talk contribs created page Coinbase Ethereum Address Typo Miserable Earth5856 (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/coinbaseethereumaddresstypomiserableearth5856.php}} thumb|CoinbaseReddit user Miserable_Earth5856 reports sending 0.5 ETH to one of CoinBase's hot wallets directly, as opposed to sending the funds to their proper deposit address. Blockchain transactions are irreversible, however these funds were sent to a wallet actively operated by the CoinBase platform. Different Reddit us...")
- 21:44, 27 January 2023 Azoundria talk contribs created page AutoShark Finance Swap Mining Vulnerability (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/autosharkfinanceswapminingvulnerability.php}} thumb|AutoShark FinanceA user was incentivized to make a large trade on the AutoShark platform based on the rebate program, which contributed heavily to the market volatility. It's unclear if there was an overall loss of any investor funds. This is a global/international case not involving a specific country. == About AutoShark...")
- 21:44, 27 January 2023 Azoundria talk contribs created page Masad Clipper And Stealer Malware (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/masadclipperandstealermalware.php}} thumb|MasadMasad Clipper and Stealer is a new form of malware which can be obtained through a malicious download. The software can obtain inforamtion about installed cryptocurrency wallets and also modify addresses in the clipboard to intercept funds. This is a global/international case not involving a specific country. == About Masad...")
- 21:44, 27 January 2023 Azoundria talk contribs created page File:Masadstealer.jpg
- 21:44, 27 January 2023 Azoundria talk contribs uploaded File:Masadstealer.jpg
- 21:43, 27 January 2023 Azoundria talk contribs created page DeversiFI EIP-1559 EthereumJS Fee Bug (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/deversifieip1559ethereumjsfeebug.php}} thumb|DeversiFIA small number of users of the DiversiFi platform were faced with unexpectedly high Ethereum transaction fees, as a result of a bug in some JavaScript libraries. For most users, they could notice that these fees were too high, or displayed in funny HEX. Most users wouldn't be able to afford the outrageous fees unless they...")
- 21:42, 27 January 2023 Azoundria talk contribs created page Bitcoin.org Double Your Cash Scam (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/bitcoinorgdoubleyourcashscam.php}} thumb|Bitcoin.orgBitcoin.org is a widely consulted reference on the bitcoin protocol and status. In September 2021, the site's DNS was redirected to a malicious server, which displayed a scam claiming to double people's money if they sent it to a particular donation address. While no post-mortem on the source of the breach was provided, do...")
- 21:42, 27 January 2023 Azoundria talk contribs created page File:Bitcoinorg.jpg
- 21:42, 27 January 2023 Azoundria talk contribs uploaded File:Bitcoinorg.jpg
- 21:42, 27 January 2023 Azoundria talk contribs created page Alpha Finance Phishing Site on Google (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/alphafinancephishingsiteongoogle.php}} thumb|Alpha FinanceAlpha Finance is a DAO which allows users to gain exposure to different projects by holding and staking their ALPHA token. Scammers created a fraudulent website with a very similar name, which was linked prominently as a Google ad. Once users would attempt to connect their wallet, they would be asked for a seed phr...")
- 21:42, 27 January 2023 Azoundria talk contribs created page File:Alphafinance.jpg
- 21:42, 27 January 2023 Azoundria talk contribs uploaded File:Alphafinance.jpg
- 21:42, 27 January 2023 Azoundria talk contribs created page Vee Finance Price Oracle Manipulation (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/veefinancepriceoraclemanipulation.php}} thumb|Vee FinanceVee Finance is a decentralized lending platform, which operates through a smart contract hot wallet. Through the creation of a fake token, the hot wallet was breached, and the funds were removed to the hacker. The Vee Finance team has since undertaken some efforts to retrieve the funds from the attacker, however there...")
- 21:41, 27 January 2023 Azoundria talk contribs created page File:Veefinance.jpg
- 21:41, 27 January 2023 Azoundria talk contribs uploaded File:Veefinance.jpg
- 21:41, 27 January 2023 Azoundria talk contribs created page PNetwork Faulty TX Processing (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/pnetworkfaultytxprocessing.php}} thumb|PNetworkpNetwork offers an automated bridge between chains. This involves the storage of crypto-assets in smart contract hot wallets to provide liquidity. One of the bridges, holding bitcoin, was successfully exploited, and 227 BTC was stolen. A compensation plan was put together including the sale of NFTs and redirecting future rewards...")
- 21:41, 27 January 2023 Azoundria talk contribs created page File:Pnetwork.jpg
- 21:41, 27 January 2023 Azoundria talk contribs uploaded File:Pnetwork.jpg
- 21:41, 27 January 2023 Azoundria talk contribs created page Defibox Hack Despite Double Audit (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/defiboxhackdespitedoubleaudit.php}} thumb|DefiboxDefibox offers a wide range of blockchain services including a swap contract. Their twice-audited smart contract for swapping still had an exploit. The incident is not mentioned on their Twitter. This is a global/international case not involving a specific country. == About Defibox == "Defibox is a one-stop DeFi application pl...")
- 21:40, 27 January 2023 Azoundria talk contribs created page File:Defibox.jpg
- 21:40, 27 January 2023 Azoundria talk contribs uploaded File:Defibox.jpg
- 21:40, 27 January 2023 Azoundria talk contribs created page SushiSwap MISO Jaypegs Automart (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/sushiswapmisojaypegsautomart.php}} thumb|SushiSwapJay Peg's Auto Mart included an NFT collection sold through the Sushiswap MISO platform. At the last minute, the contract was modified to send funds to the account of a developer. It took a while to detect the issue, and the developer initially denied what had happened, however they quickly came around to repaying the funds....")
- 21:40, 27 January 2023 Azoundria talk contribs created page NowSwap Protocol Logic Error (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/nowswapprotocollogicerror.php}} thumb|NowSwapThe NowSwap protocol stored customer funds in their smart contract hot wallets, which was not only not audited but closed source. Due to an exploit, a vulnerability which was apparently similar to one exploited in April on Uranium Finance, $1m in assets were stolen. This is a global/international case not involving a specific count...")
- 21:40, 27 January 2023 Azoundria talk contribs created page File:Nowswap.jpg
- 21:40, 27 January 2023 Azoundria talk contribs uploaded File:Nowswap.jpg
- 15:27, 27 January 2023 Azoundria talk contribs created page GrowingFi Withdraw Not Checked (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/growingfiwithdrawnotchecked.php}} thumb|GrowingFiDespite an audit from CertiK, the GrowingFi platform smart contract hot wallet still suffered a significant theft. The platform ran multiple attempts to create a recovery for their affected users and it appears they may have compensated a large portion of the funds, though nowhere near all of them. This is a global/internatio...")
- 15:27, 27 January 2023 Azoundria talk contribs created page File:Growingfi.jpg
- 15:27, 27 January 2023 Azoundria talk contribs uploaded File:Growingfi.jpg
- 15:27, 27 January 2023 Azoundria talk contribs created page Secret Swap Secret Breach (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/secretswapsecretbreach.php}} thumb|Secret SwapThe Secret Swap platform allows exchange of Secret assets on the Secret Network (validated by Secret Agents). The bridge took advantage of Secret Smart Contract Hot Wallets as bridges. The exact breach which occurred is a Secret (no post mortem) but luckily the resulting blockchain is also being kept secret (rolled back). This m...")
- 15:27, 27 January 2023 Azoundria talk contribs created page File:Secretswap.jpg
- 15:27, 27 January 2023 Azoundria talk contribs uploaded File:Secretswap.jpg
- 15:27, 27 January 2023 Azoundria talk contribs created page Zabu Finance Staking Calculation Bug (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/zabufinancestakingcalculationbug.php}} thumb|Zabu FinanceZabu Finance created a large liquidity pool for the Avalanche blockchain. As is typical in exploited cases, funds were stored in a large smart contract hot wallet. In this case, there was an exploit around deflationary token handling. The team used a snapshot to re-issue tokens in an attempt to compensate affected us...")
- 15:26, 27 January 2023 Azoundria talk contribs created page File:Zabufinance.jpg
- 15:26, 27 January 2023 Azoundria talk contribs uploaded File:Zabufinance.jpg
- 15:26, 27 January 2023 Azoundria talk contribs created page Ledger Wallet Cleared Out TuckerCR (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/ledgerwalletclearedouttuckercr.php}} thumb|LedgerReddit user TuckerCR was tricked into divulging his seed phrase to a scammer on Telegram. He was directed to a website which appeared legitimate and allowed him to enter his seed phrase, after which his funds were immediately removed from the account. He reportedly lost $350k orth of BTC and ETH. This is a global/international c...")
- 15:26, 27 January 2023 Azoundria talk contribs created page AFK Finance Goes AFK (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/afkfinancegoesafk.php}} thumb|AFK Systems FinanceAs a completely anonymous team, AFK Systems Finance launched a new platform including a vault, with known exploits in the smart contract hot wallet. They then got a couple of smart contract auditors to audit the smart contract, presumably until they found one which wouldn't do the audit right away. When the audit results came...")
- 15:26, 27 January 2023 Azoundria talk contribs created page File:Afkfinance.jpg
- 15:26, 27 January 2023 Azoundria talk contribs uploaded File:Afkfinance.jpg
- 15:26, 27 January 2023 Azoundria talk contribs created page DYdX Pledge Contract Bug (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/dydxpledgecontractbug.php}} thumb|DYdXThe audited dYdX contract was launched with an incorrect ratio, which prevented users from performing withdrawals as anticipated. Funds were locked in the smart contract, and all are recoverable. This is a global/international case not involving a specific country. == About DYdX == "Perpetuals, decentralized." "Trade Perpetual Contracts wit...")
- 15:25, 27 January 2023 Azoundria talk contribs created page File:Dydx.jpg
- 15:25, 27 January 2023 Azoundria talk contribs uploaded File:Dydx.jpg
- 15:24, 27 January 2023 Azoundria talk contribs created page OpenZeppelin UUPS Proxy Initialization Vulnerability (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openzeppelinuupsproxyinitializationvulnerability.php}} thumb|OpenZeppelinThe OpenZeppelin smart contract framework had a vulnerability which would allow an adversary to take over the smart contract, if it hadn't been initialized yet. It's unclear if it was possible to take any funds using this method, however it was certainly possible to destroy existing smart contracts,...")
- 15:24, 27 January 2023 Azoundria talk contribs created page Convex Finance Malicious Search Results (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/convexfinancemalicioussearchresults.php}} thumb|Convex FinanceConvex Finance is a tool to increase rewards for stakers and liquidity providers on the curve protocol. Malicious entities made a copy of their website on a similar domain name, which most likely attempted to trick users into making payments or divulging their seed phrase. It is unclear if any funds were succe...")
- 15:24, 27 January 2023 Azoundria talk contribs created page File:Convexfinance.jpg
- 15:24, 27 January 2023 Azoundria talk contribs uploaded File:Convexfinance.jpg
- 15:24, 27 January 2023 Azoundria talk contribs created page DAO Maker Insufficient Authentication (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/daomakerinsufficientauthentication.php}} thumb|DAO MakerDAO Maker ran a service to enable other projects to launch coins and gain funding. All the token funds were stored in smart contract hot wallets, and the team decided that they didn't need to check who was calling the init function. A hacker decided they would like to initialize some of these wallets for themselves, and...")
- 15:24, 27 January 2023 Azoundria talk contribs created page Siren Market Reentrancy Bug (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/sirenmarketreentrancybug.php}} thumb|Siren MarketSiren Market is a decentralized protocol for options. The decision was made to store all funds in a smart contract hot wallet, based on the certainty of the audit by QuantStamp. However, this missed an exploit since it was in "an unusual spot". Therefore, all users face the loss of their funds unless the attacker returns t...")