Scan to download
BTC $71,829.53 -2.79%
ETH $1,975.78 -2.34%
BNB $690.09 -5.44%
XRP $1.30 -3.59%
SOL $80.25 -3.17%
TRX $0.3491 +0.24%
DOGE $0.0995 -1.40%
ADA $0.2296 -3.24%
BCH $283.17 -6.85%
LINK $8.94 -3.13%
HYPE $73.13 +7.31%
AAVE $80.51 -2.70%
SUI $0.8715 -3.62%
XLM $0.2659 +0.52%
ZEC $540.09 -1.72%
BTC $71,829.53 -2.79%
ETH $1,975.78 -2.34%
BNB $690.09 -5.44%
XRP $1.30 -3.59%
SOL $80.25 -3.17%
TRX $0.3491 +0.24%
DOGE $0.0995 -1.40%
ADA $0.2296 -3.24%
BCH $283.17 -6.85%
LINK $8.94 -3.13%
HYPE $73.13 +7.31%
AAVE $80.51 -2.70%
SUI $0.8715 -3.62%
XLM $0.2659 +0.52%
ZEC $540.09 -1.72%

stolen

TAC: About 90% of the stolen assets have been recovered, and the cross-chain bridge will resume operation after the audit is completed

The TON Network expansion project TAC has disclosed that a security incident occurred with the TON-TAC asset bridge on May 11. Four days later, approximately 80% of the affected assets have been returned. TAC today released a post-incident analysis report detailing the events. The root cause of the vulnerability was a lack of a single verification in the sorter software: the attacker deployed a counterfeit Jetton wallet on TON, and the sorter accepted the counterfeit tokens because it did not verify the code hash of the sender's wallet. The total loss was approximately $2.86 million, involving USDT, BLUM, and tsTON. Following a public appeal, about 90% of the assets were returned to the multi-signature address controlled by TAC on May 14, with the remaining 10% retained by the attacker.The cross-chain bridge remains paused, awaiting independent review of the repaired sorter software by the auditing party and TON partners. Cross-chain operations will resume once the verification of the repaired software is completed and the gap is filled with recovered assets and TAC Foundation token reserves. Due to the need for multi-party coordination, a precise timeline cannot be provided. The remaining funding gap will be filled by the TAC Foundation treasury, ensuring that users and protocols incur no financial losses. TAC reminds users that official updates are only published through this account and Telegram, and any unsolicited "recovery" or "support" private messages are scams.

U.S. judge postpones hearing on Aave's application to unfreeze $71 million in stolen ETH

U.S. Judge Margaret M. Garnett in New York postponed the ruling on Aave's emergency application on Wednesday, which aims to unfreeze $71 million in ETH related to the Kelp DAO hacking incident, and requested both parties to submit supplemental briefs before the hearing on June 5. Aave is attempting to reclaim the $71 million in ETH frozen on Arbitrum to assist in the asset recovery efforts from this hacking incident—Kelp DAO suffered losses of up to $293 million from the hack, making it one of the most severe security incidents in the DeFi space this year.However, the U.S. law firm Gerstein Harrow LLP submitted a restraining order to the court in early May, claiming that its client has rights to the aforementioned funds. Aave then filed an emergency motion to lift the freeze, warning that if the funds are not released in a timely manner, it could lead to user liquidations and potentially impact the entire DeFi market. Judge Garnett noted in her ruling that Aave failed to adequately explain how user funds would incur "compound losses" if the restraining order remained in place. She also acknowledged the complexity of the case, the risks faced by the victims, and requested both parties to provide supplemental statements on six key issues, including: whether the hacking transaction is subject to New York state sanctuary principles, the legal distinctions between fraud and theft and what rights the hacker has over the stolen assets, which laws apply to determine the priority of claims for frozen assets, whether constructive trusts are an appropriate remedy, and whether Aave or Arbitrum can identify individual victims and proportionally return assets. Both parties must submit supplemental briefs by May 22.Meanwhile, the overall compensation work for Kelp DAO is progressing. Kelp and Aave announced on Tuesday that the rsETH held by the hacker has been destroyed on Arbitrum, and approximately $278 million in loss tokens will be restored within the next two weeks through the funds of the Aave Recovery Guardian multi-signature wallet. Once the relevant smart contracts are reactivated, all functions of rsETH will return to normal.
app_icon
ChainCatcher Building the Web3 world with innovations.