Ariva Digital Key Breached
Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' section to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Ariva Digital was a blockchain project with a focus on tourism and travel. One of their staking contracts was breached, presumably due to a private key breach. All assets were liquidated via TornadoCash. According to the team, they have enough funds to reimburse all affected users, although KYC will be required to get any funds. They are apparently working on fund recovery, although there is no indication that the perpetrators have been identified.
This is a global/international case not involving a specific country.
About Ariva Digital
"Ariva is a cryptocurrency launched by Ariva Co., produced for active use in global and local tourism and travel networks in the near future. Project is a worldwide B2C travel & tourism network where members can meet with global and local tourism service providers in the light of previous travelers' experiences and comments, make bookings with cryptocurrencies, and earn crypto money from both their reservations and valuable content sharing."
"With the arrival of ARIVA, the digital payment system is about to experience a massive innovative turnaround that can change the world and make trading easier and better. ARV came into existence with the intention to make transactions hassle-free in global and local tourism networks in the near future."
"The project aims at achieving active use in the tourism and travel industry, which is one of the largest and most important industries of the world economy, although none of the previously produced cryptocurrencies have been targeted. Out to be the game-changer in the cryptocurrency world, ARIVA’s aim is not only to produce a cryptocurrency trade on exchange but to ensure that ARV is actively used in the tourism industry."
"Blockchain security firm PeckShield revealed on February 25 that developers behind Ariva Digital ($ARV) have withdrawn the Token from the staking contract and swapped it to 1,700 WBNB."
"Dear Ariva Family, we regret to inform you that one of our staking wallets was hacked last night. Our software security team has completed the necessary investigations and the cause of the leak has been determined."
"The @ArivaCoin's rugged funds 1,710 BNB (~$600k) have been deposited to @TornadoCash."
"Ariva has ample funding and power to handle this. As Ariva Team, we undertake that none of our investors will be victims. Ariva Staking Factory will not be active for a few days due to security measures."
"Thanks to the meticulous work of our entire team and legal department and the exchanges that did not spare their support, we have reached some very important footprints of the perpetrators."
"We've already initiated the criminal procedure through our lawyers against the perpetrators and presented our complaints to the police and other governmental institutions."
"As a result of our investigation of the staking contract, we have detected more than one suspicious transaction, so we will not activate the ASF temporarily."
"For maximum security, all refunds will be made as a direct transfer following a KYC verification and wallet review." "[W]e're not going anywhere, we're just getting started."
This is a global/international case not involving a specific country.
The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.
Include:
- Known history of when and how the service was started.
- What problems does the company or service claim to solve?
- What marketing materials were used by the firm or business?
- Audits performed, and excerpts that may have been included.
- Business registration documents shown (fake or legitimate).
- How were people recruited to participate?
- Public warnings and announcements prior to the event.
Don't Include:
- Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
- Anything that wasn't reasonably knowable at the time of the event.
There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.
The Reality
This sections is included if a case involved deception or information that was unknown at the time. Examples include:
- When the service was actually started (if different than the "official story").
- Who actually ran a service and their own personal history.
- How the service was structured behind the scenes. (For example, there was no "trading bot".)
- Details of what audits reported and how vulnerabilities were missed during auditing.
What Happened
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.
| Date | Event | Description |
|---|---|---|
| February 25th, 2022 2:21:00 AM | Main Event | Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here. |
Total Amount Lost
The total amount lost has been estimated at $637,000 USD.
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?
Immediate Reactions
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?
Ultimate Outcome
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?
Total Amount Recovered
The total amount recovered is unknown.
What funds were recovered? What funds were reimbursed for those affected users?
Ongoing Developments
What parts of this case are still remaining to be concluded?
Prevention Policies
The way to protect the project was simple - use a multi-sig. The problem appears to have come about because there was only one key, and that key was compromised. Our framework proposes that uninsured user funds be placed in an offline multi-signature wallet, held by known trained individuals.
References
ARIVA (ARV) The new generation Travel & Tourism cryptocurrency - YouTube (Mar 3)
@ArivaCoin Twitter (Mar 3)
@PeckShieldAlert Twitter (Mar 3)
https://bscscan.com/address/0xcb25e1927d1fcc0beb11b492b96b0a351216260e (Mar 3)
@ArivaCoin Twitter (Mar 3)
https://coinmarketcap.com/currencies/bnb/historical-data/ (Feb 15)