All public logs
Jump to navigation
Jump to search
Combined display of all available logs of Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository. You can narrow down the view by selecting a log type, the username (case-sensitive), or the affected page (also case-sensitive).
- 15:20, 27 January 2023 Azoundria talk contribs created page Coinbase Vidovic Account Sim Swap (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/coinbasevidovicaccountsimswap.php}} thumb|CoinbaseCoinbase is the largest exchange platform in the United States. Cryptocurrency investors Tanja and Jared Vidovic had grown an investment to nearly $170k, and secured their accounts with SMS-based two-factor authentication. The attacker was able to trick their cell phone provider into switching the phone service to a new phone,...")
- 15:20, 27 January 2023 Azoundria talk contribs created page OpenSea Fake Support Accounts (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openseafakesupportaccounts.php}} thumb|OpenSeaOpenSea is one of the largest NFT marketplaces in the world. In August 2021, an OpenSea user fell for an advanced social engineering ploy where the scammers pretended to be an entire OpenSea support team with multiple idle staff on Discord. The end goal of the scam is to get the victim to display their QR code for syncing with Mobi...")
- 15:19, 27 January 2023 Azoundria talk contribs created page OpenZeppelin Timelock Reentrancy Vulnerability (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openzeppelintimelockreentrancyvulnerability.php}} thumb|OpenZeppelinIt was uncovered that OpenZeppelin, a well-known smart contract audit provider, had a critical vulnerability in their smart contract, which would have allowed privilege escallation. This was found through a bug bounty program, and not exploited, so no funds were lost. A significant number of projects all...")
- 15:19, 27 January 2023 Azoundria talk contribs created page File:Openzeppelin.jpg
- 15:19, 27 January 2023 Azoundria talk contribs uploaded File:Openzeppelin.jpg
- 15:19, 27 January 2023 Azoundria talk contribs created page Luna Yield Rug Pull (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/lunayieldrugpull.php}} thumb|Luna YieldLuna Yield was another yield optimizing service, where users provided liquidity in a smart contract hot wallet. After the smart contract was exploited, the anonymous team provided affected users 60% of their invested USDC back. Social media accounts were also deleted. This is a global/international case not involving a specific country...")
- 15:19, 27 January 2023 Azoundria talk contribs created page File:Lunayield.jpg
- 15:19, 27 January 2023 Azoundria talk contribs uploaded File:Lunayield.jpg
- 15:18, 27 January 2023 Azoundria talk contribs created page Solend Insecure Authentication Check (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/solendinsecureauthenticationcheck.php}} thumb|SolendSolend is a lending protocol for Solana. The smart contract hot wallets had a vulnerability which allowed an attacker to escalate their permissions and change configuration parameters in a new lending market. This would have allowed them to steal the funds of users on a much larger scale. Luckily, the issue was detected early,...")
- 15:18, 27 January 2023 Azoundria talk contribs created page File:Solend.jpg
- 15:18, 27 January 2023 Azoundria talk contribs uploaded File:Solend.jpg
- 15:18, 27 January 2023 Azoundria talk contribs created page BSCToken Scam Website (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/bsctokenscamwebsite.php}} thumb|BSCTokenThe BSCToken website is a phishing site designed to trick users to give access to their wallet, where funds will be withdrawn. This is a global/international case not involving a specific country. == About BSCToken == "Leveraged yield farming with the BSCTOKEN. BSC Token Finance is a regulated Company. All you need to do in order to e...")
- 15:18, 27 January 2023 Azoundria talk contribs created page File:Bsctoken.jpg
- 15:18, 27 January 2023 Azoundria talk contribs uploaded File:Bsctoken.jpg
- 15:17, 27 January 2023 Azoundria talk contribs created page Liquid Warm Wallet Liquidated (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/liquidwarmwalletliquidated.php}} thumb|LiquidLiquid is one of the largest exchanges globally. Hackers were able to access their warm wallets and complete the withdrawal of all assets, most likely by simply requesting a series of withdrawals once they gained access to the system. Despite using multi-sig, all of the factors evidently were breached by the single hacker, and likely...")
- 15:17, 27 January 2023 Azoundria talk contribs created page Pinecone Finance Deflation Hack (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/pineconefinancedeflationhack.php}} thumb|Pinecone FinancePinecone Finance offers a new yield farm for staking, where users deposit their funds into a smart contract hot wallet, earning profit by providing market liquidity. There was an exploit which was possible with deflationary tokens, where a hacker was able to gain $200k. The hacker returned the funds in a subsequ...")
- 15:17, 27 January 2023 Azoundria talk contribs created page File:Pineconefinance.jpg
- 15:17, 27 January 2023 Azoundria talk contribs uploaded File:Pineconefinance.jpg
- 15:16, 27 January 2023 Azoundria talk contribs created page SushiSwap MISO White Hat Diffusal (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/sushiswapmisowhitehatdiffusal.php}} thumb|SushiSwapThe SushiSwap MISO is a smart contract which assists with launching new coins and tokens which are managed through a smart contract hot wallet. The contract underwent 3 separate audits by reputable firms as well as multiple security researchers had reviewed it. And yet, there was still a bug found which would have been able...")
- 15:16, 27 January 2023 Azoundria talk contribs created page XSurge Reentrancy Attack (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/xsurgereentrancyattack.php}} thumb|XSurgeThe XSurge smart contract was exploited and $5m was taken from investors. It appears that XSurge is making efforts to recompensate affected users. They put out an initial snapshot of balances to be compensated. They also completed an audit with CertiK. This is a global/international case not involving a specific country. == About XSur...")
- 15:16, 27 January 2023 Azoundria talk contribs created page File:Xsurge.jpg
- 15:16, 27 January 2023 Azoundria talk contribs uploaded File:Xsurge.jpg
- 15:15, 27 January 2023 Azoundria talk contribs created page Curve Bribe Exploit (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/curvebribeexploit.php}} thumb|Curve FinanceThe Curve Bribe utility allows bribing Curve holders to vote a certain way in the decentralized governance protocol. The assets were stored in a smart contract hot wallet, and this was breachable. A white hack was performed to extract the funds, which were put in a new contract. This is a global/international case not involving...")
- 15:15, 27 January 2023 Azoundria talk contribs created page Ref Finance Logic Error (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/reffinancelogicerror.php}} thumb|Ref FinanceRef Finance offers a variety of products and services on the NEAR protocol. After releasing a "hotfix" to their protocol, a vulnerability was introduced which allowed for the theft of a significant amount of NEAR and REF tokens from their smart contract hot wallet. The REF token was forked to eliminate the stolen tokens, and the N...")
- 15:15, 27 January 2023 Azoundria talk contribs created page File:Reffinance.jpg
- 15:15, 27 January 2023 Azoundria talk contribs uploaded File:Reffinance.jpg
- 15:15, 27 January 2023 Azoundria talk contribs created page Pixel-Track Hex Tokens Stolen (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/pixeltrackhextokensstolen.php}} thumb|MetaMaskReddit user Pixel-Track introduces themselves as someone from an older generation who is not experienced with cryptocurrency. They reported that they did not share their seed phrase or private key with anyone, however they were attempting to stake their HEX tokens and this was not successful. They report that their funds were take...")
- 15:14, 27 January 2023 Azoundria talk contribs created page Dao Maker Exploit (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/daomakerexploit.php}} thumb|Dao MakerDAO Maker offers a comprehensive suite of DeFi products. One of the admin keys was exploited, in order to steal the funds of users stored in the platform. Ultimately, the team came up with a recovery plan for all affected users, and also restructured the smart contract such that no funds were under their custody, eliminating the centraliz...")
- 15:14, 27 January 2023 Azoundria talk contribs created page File:Daomaker.jpg
- 15:14, 27 January 2023 Azoundria talk contribs uploaded File:Daomaker.jpg
- 15:14, 27 January 2023 Azoundria talk contribs created page Shazbot /Yoda NFT Wallet Compromised (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/shazbotyodanftwalletcompromised.php}} thumb|MetaMaskAn NFT collector who goes by the name Yoda was tricked into revealing their private key seed phrase via a discord scam. While they didn't click "Next", the key was still entered into a live website. A significant quantity of NFTs were taken, however this was less than half of the NFTs present in their account at the time. Th...")
- 15:14, 27 January 2023 Azoundria talk contribs created page Poly Network Validation Error (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/polynetworkvalidationerror.php}} thumb|Poly NetworkThe Poly Network allows different smart chains to interact with one another securely. However, it contained a vulnerability which allowed funds to be removed. A hacker exploited the vulnerability, messed up their transactions such that their identity became known, and then proceeded to return the funds in exchange for a $5...")
- 15:13, 27 January 2023 Azoundria talk contribs created page File:Polynetwork.jpg
- 15:13, 27 January 2023 Azoundria talk contribs uploaded File:Polynetwork.jpg
- 15:13, 27 January 2023 Azoundria talk contribs created page Punk Protocol Reinitialized (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/punkprotocolreinitialized.php}} thumb|Punk ProtocolThe Punk Protocol is a decentralized annuity protocol, which allows investors to contribute and pays out periodic regular cash flows. All funds were stored in a smart contract hot wallet. A malicious hacker found an exploit, allowing them to reinitialize the smart contract hot wallet. However, while their transaction sat...")
- 15:13, 27 January 2023 Azoundria talk contribs created page File:Punkprotocol.jpg
- 15:13, 27 January 2023 Azoundria talk contribs uploaded File:Punkprotocol.jpg
- 15:13, 27 January 2023 Azoundria talk contribs created page Zerogoki Price Oracle Compromised (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/zerogokipriceoraclecompromised.php}} thumb|ZerogokiThe Zerogoki project is an experimental leveraged token trading platform. An attacker was able to somehow craft a compromised price oracle, which according to analysis shows that it was signed by valid keys. It is unclear how the attacker was able to sign a valid transaction. The most likely scenario would be that all keys we...")
- 15:12, 27 January 2023 Azoundria talk contribs created page File:Zerogoki.jpg
- 15:12, 27 January 2023 Azoundria talk contribs uploaded File:Zerogoki.jpg
- 15:12, 27 January 2023 Azoundria talk contribs created page OpenSea Fraudulent NFT Listing (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openseafraudulentnftlisting.php}} thumb|OpenSeaIn August 2021, a fraudulent listing on the OpenSea NFT marketplace attracted more than 40 buyers of fake 24px cats NFTs. There is no way for those affected to recover their assets. This is a global/international case not involving a specific country. == About OpenSea == "The world’s first and largest digital marketplace for c...")
- 15:12, 27 January 2023 Azoundria talk contribs created page File:Opensea.jpg
- 15:12, 27 January 2023 Azoundria talk contribs uploaded File:Opensea.jpg
- 15:11, 27 January 2023 Azoundria talk contribs created page Casper DeFi Malicious Backdoor Mint (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/casperdefimaliciousbackdoormint.php}} thumb|Casper DeFiCasper Defi launched a simple investing platform where all funds can be stored in a smart contract hot wallet. One of their developers who made the contract added a backdoor durign the migration. This gave him the ability to mint tokens, which he used to drain all the stored liquidity. Since he had worked as a develope...")
- 15:11, 27 January 2023 Azoundria talk contribs created page File:Casperdefi.jpg
- 15:11, 27 January 2023 Azoundria talk contribs uploaded File:Casperdefi.jpg
- 15:11, 27 January 2023 Azoundria talk contribs created page Wault Finance Stablecoin Peg Logic Error (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/waultfinancestablecoinpeglogicerror.php}} thumb|Wault FinanceWault Finance offers a financial service which included a stablecoin. Liquidity was backed by funds in a smart contract hot wallet. Through flash loans and price manipulation, an attacker was able to remove liquidity, with the announcement of the hack triggering a price crash. No user funds were lost in the att...")
- 15:11, 27 January 2023 Azoundria talk contribs created page File:Waultfinance.jpg
- 15:11, 27 January 2023 Azoundria talk contribs uploaded File:Waultfinance.jpg
- 15:10, 27 January 2023 Azoundria talk contribs created page BSV 51% Attack Repelled (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/bsv51attackrepelled.php}} thumb|Bitcoin AssociationThe bitcoin SV blockchain underwent a reorganization, when a hacker was able to gain more computational power than the rest of the network. The Bitcoin Association acted by requesting all node operators to discard the longer chain, which created a period of confusion where different nodes were mining different chain...")