Farcana Liquidity Provider Wallet Breach

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search

Notice: This page is a freshly imported case study from an original repository. While the original content had a similar format, some sections may not have been fully completed. Please help fill in any empty sections or any missing information you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!

Farcana Logo/Homepage

Farcana is a competitive, fast-paced hero shooter, with battles settled on the blockchain in bitcoin. A wallet belonging to one of the liquidity providers for Farcana was breached, and this was reported by the company. The news was picked up and widely distributed, under the false understanding that the waller was somehow owned by the Farcana platform itself. The original tweet was deleted and operations of the project resumed.[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17][18][19][20][21]

About Farcana

"Farcana is an immersive, fast-paced, competitive hero shooter with an emphasis on quick movement and fast, tactical decision-making. While your weapons will do a lot of the talking, achieving victory will require strategic use of your abilities and tight teamwork!"

"Farcana stands as a prominent gaming studio nestled in the heart of the UAE, boasting a collective of over 120 exceptionally skilled professionals, comprising highly experienced game developers and industry experts. Together, we seamlessly intertwine blockchain technology with conventional game development. Our goal is set to elevate player immersion and be a key player in re-defining gaming. Spearheading this endeavor is our team shooter, Farcana, which harnesses the power of web3 technologies. We put the reins of the game economy, marketplace, and asset ownership entirely in the hands of our players. We aim to etch our mark in shaping the future landscape of gaming."

The Reality

This sections is included if a case involved deception or information that was unknown at the time. Examples include:

  • When the service was actually started (if different than the "official story").
  • Who actually ran a service and their own personal history.
  • How the service was structured behind the scenes. (For example, there was no "trading bot".)
  • Details of what audits reported and how vulnerabilities were missed during auditing.

What Happened

"On June 24, the UAE-based blockchain gaming studio Farcana tweeted that one of their FAR wallets was hacked."

Key Event Timeline - Farcana Liquidity Provider Wallet Breach
Date Event Description
June 19th, 2024 10:25:03 AM MDT Polygon Blockchain Transaction The transaction on the polygon blockchain, as reported by CertiK.
June 23rd, 2024 7:34:48 PM MDT Farcana Tweet Posted The Farcana team posts a tweet to notify the community that one of the Farcana wallets has been compromised. This tweet would later be deleted.
June 24th, 2024 1:50:00 AM MDT Tweet Against Fraud Farcana notifies the community to be vigilant against fake accounts, which are sharing links.
June 24th, 2024 6:28:00 AM MDT Clarification Tweet The Farcana team clarifies that the wallet belonged to one of their liquidity providers and that their system has not been breached.
June 24th, 2024 10:56:00 PM MDT ZachXBT Criticism ZachXBT tweets to criticize the project and how they have posted and then deleted their original announcement.
June 26th, 2024 4:26:00 AM MDT Tweet Update "The incident is still being investigated and Farcana is working with relevant stakeholders to determine what precisely transpired. However, nothing about the incident compromises the functioning of the project, and is not materially consequential to the price of FAR. This is why operations have resumed."

Technical Details

This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?

Total Amount Lost

The total amount lost has been estimated at $880,000 USD.

How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?

Immediate Reactions

"On June 24, the UAE-based blockchain gaming studio Farcana tweeted that one of their FAR wallets was hacked. On the same day, Farcana tweeted a clarification stating that it was a third-party market maker that was attacked, and the official wallet and FAR smart-contract had not experienced any exploits."

"Security Alert: $FAR Wallet Hacked"

"Although Farcana did not lose any funds directly, a third-party market maker was hacked, resulting in the theft of 23,809,523 FAR tokens valued at nearly $880,000. This incident underscores the vulnerability of third-party services."

"We regret to inform our community that one of the $FAR wallets has been compromised. Our team is working tirelessly to address the breach and ensure the safety of your assets. Deposits to all CEX’es are frozen until the issues solved."

Ultimate Outcome

"Earlier today, Bybit and Gate resumed deposits of FAR. All operations related to the token are back to normal.FAR token is approximately 25% lower in price over the last 5 days, (prior to the incident) and largely in line with the broader market."

"23,809,523 FAR was transferred to 0x9681 before a large amount of tokens were sold

The majority of USDT received from selling was moved to 0x6454

Exploiter still hols ~5.2m FAR tokens"

Total Amount Recovered

There do not appear to have been any funds recovered in this case.

What funds were recovered? What funds were reimbursed for those affected users?

Ongoing Developments

What parts of this case are still remaining to be concluded?

Individual Prevention Policies

No specific policies for individual prevention have yet been identified in this case.

For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.

Platform Prevention Policies

Policies for platforms to take to prevent this situation have not yet been selected in this case.

For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.

Regulatory Prevention Policies

No specific regulatory policies have yet been identified in this case.

For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.

References

  1. SlowMist Hacked - SlowMist Zone (Accessed Jun 25, 2024)
  2. @FarcanaOfficial Twitter (Accessed Jun 28, 2024)
  3. @FarcanaOfficial Twitter (Accessed Jun 28, 2024)
  4. @FarcanaOfficial Twitter (Accessed Jun 28, 2024)
  5. @FarcanaOfficial Twitter (Accessed Jun 28, 2024)
  6. @FarcanaOfficial Twitter (Accessed Jun 28, 2024)
  7. @FarcanaOfficial Twitter (Accessed Jun 28, 2024)
  8. @zachxbt Twitter (Accessed Jun 28, 2024)
  9. @FarcanaOfficial Twitter (Accessed Jun 28, 2024)
  10. @0xCommitAudits Twitter (Accessed Jun 28, 2024)
  11. @FarcanaOfficial Twitter (Accessed Jun 28, 2024)
  12. @ChainLight_io Twitter (Accessed Jun 28, 2024)
  13. @CertiKAlert Twitter (Accessed Jun 28, 2024)
  14. Polygon PoS Chain Transaction Hash (Txhash) Details | PolygonScan (Accessed Jun 28, 2024)
  15. @arunim_shukla Twitter (Accessed Jun 28, 2024)
  16. @ItsBitcoinWorld Twitter (Accessed Jun 28, 2024)
  17. Farcana Exploiter 3 | Address 0x6454db572ac0cec0f11dc5ec86319ee776b669cf | PolygonScan (Accessed Jun 28, 2024)
  18. @CertiKAlert Twitter (Accessed Jun 28, 2024)
  19. Farcana | Twitter, Instagram, TikTok | Linktree (Accessed Jun 28, 2024)
  20. - YouTube (Accessed Jun 28, 2024)
  21. Company | Boast Your Skills In Farcana, Team-Based Hero Shooter (Accessed Jun 28, 2024)