A loophole in the code allowed a hacker to drain funds worth roughly $455,000 from Arcadia’s Ethereum and Optimism vaults. Arcadia Finance confirmed the hack two hours after PeckShield’s intimation, and subsequently paused the contracts to prevent further bleeding of funds.
Most of the stolen funds were from Optimism — approximately 180 Ether, and have been washed via Tornado Cash. However, the stolen tokens on Ethereum — worth over $103,000 at the time of writing — remain parked at the suspected wallet address.
While investigations are underway, Arcadia’s code houses another vulnerability, which could prove catastrophic for the protocol if exploited. According to PeckShield, there is a lack of reentrancy protection, which allows for the instant liquidation to bypass the internal vault health check.”
Advertisement
The team, however, told Cointelegraph that the root cause pointed out by PeckShield is wrong.
ZachXBT’s Research Cited In Canadian NFT Rug Pull Class-Action Lawsuit
An alleged $3.1 million non-fungible token (NFT) rug pull by Boneheads has been the subject of a class-action lawsuit in Canada, and ZachXBT’s independent Blockchain sleuth work has been referenced there.
ZachXBT highlighted in a Tweet recently that the Boneheads team “quickly disappeared and spent the mint funds on BAYCs [Bored Ape Yacht Club NFTs], luxury goods, and other items never fulfilling the roadmap”.
“Yet another case where my research has been cited,” ZachXBT added.
Advertisement
The initial class-action case was filed in mid-June in the Ontario Superior Court of Justice. According to the statement of claim dated June 19, the Boneheads team has been charged with breach of contract with investors for, among other things, failing to follow the project’s plan, misappropriating money, engaging in fraudulent misrepresentation, and careless misrepresentation.
“As of the date of filing of this claim, the Boneheads NFT team has not delivered on a single roadmap promise they had made to Boneheads NFT purchasers,” the filing reads.
“Consumers have not received a single NFT airdrop, token, physical collectible, marketplace access, forging, avatar application, voting right, giveaway, or the dozens of other promises that were made to consumers in consideration for purchasing or minting a Boneheads NFT,” it adds.
NFTs Worth $765k Stolen In SIM Swap Attack
Over $765,000 worth of NFTs were stolen after a SIM swap attack on Gutter Cat Gang. The bad actors used a fake Gutter Cat Gang airdrop scam to drain people’s wallets, with at least $700,000 worth of NFTs stolen from a single address.
Around 8:00 p.m. UTC on July 7, numerous members of the NFT community brought attention to the security lapse.
Gutter Cat Gang co-founder Gutter Mitch said in a Tweet: “Our Twitter has been compromised please do not interact with any links.”
Co-founder Gutter Ric’s account was also hacked in addition to the Gutter Cat Gang’s official account.
Advertisement
The hackers made use of the accounts to spread links to phony limited edition Gutter Cat Gang NFT shoe airdrops, which when clicked on ultimately drained users’ cash.
The tweets featured the Gutter Cat Gang logo and images from the project’s physical sneaker drop in collaboration with Puma and NBA/Charlotte Hornets star LaMelo Ball to give the fake connections more credibility.