This Protocol on Coinbase’s Base Was Hacked Just 6 Days After Layer 2 Launch

2023-8-15 13:45

The crypto community has lashed out at the RocketSwap team after a 472 Ethereum (ETH) was taken following a private key compromise.

Coinbase Base drew enthusiasm from many developers and users when it debuted. The Layer 2 protocol launched with over 100 decentralized applications (dApps), but within a week, the projects are becoming a favorite target of scammers.

RocketSwap Disables Comments and Telegram After Exploit 

According to the Web3 security firm Beosin, hackers stole over 472 ETH (approx. $869,000) from the decentralized exchange (DEX) RocketSwap. 

The exploiters accessed the funds via a compromise in the private keys. Then they bridged the tokens to Ethereum through the Stargate bridge. The screenshot below shows the flow of the funds prepared by Beosin.

The flow of the funds stolen from RocketSwap. Source: X (Twitter)

RocketSwap apologized to the users for the loss and explained:

“A brute force hack of the server was detected, and due to the proxy contract used for the farm contract, there were multiple high-risk permissions that led to the transfer of the farm’s assets.”

Furthermore, the project disabled comments on X (Twitter) and Telegram. The team faced heavy criticism from the community for disabling the communication after the exploit. An X (Twitter) user wrote:

“Probably the worst hack reaction I have ever seen. They shut down the Telegram and finish the tweet with:

“We are very sorry for your loss”

Like they don’t have anything to do with it”

The Total Value Locked (TVL) on RocketSwap is down by more than 25% in the past 24 hours. According to DefiLlama, the TVL currently stands at around $2.48 million after the sharp decline.

RocketSwap TVL. Source DefiLlama Irresponsible Security Standards

For Web3 projects, and even for individuals, the storage of private keys is the most essential security measure. Ideally, private keys or secret key phrases should be stored offline to minimize the chances of a compromise.

RocketSwap put the private keys on a server leading to the compromise. The poor security measure has invited widespread criticism from community members.

Community’s reaction to RocketSwap’s security. Source: X (Twitter)

Some other security blunders by RocketSwap have also come to light following the recent exploit. On Aug. 8, a community member shared screenshots of deleted posts from RocketSwap, which showed the team admitting to transferring $69,000 worth of native tokens (RCKT) to scammers.

The scammers, disguised as KuCoin team members, claimed that they wanted to list the RCKT tokens and asked the team to send tokens for liquidity market making. The RocketSwap team realized they had been scammed due to the sell-off after sending the tokens.  

Community member Dashen De Silva believes the team sold tokens for their benefit and used “fabricated narrative as a cover.”

RocketSwap’s deleted post. Source: X (Twitter) A Rug pull?

With two back-to-back incidents within eight days, the community suspects that the RocketSwap team might have conducted a rug pull.

Click here to learn more about rug pull.

An X (Twitter) user, Forgiving, believes that RCKT was a “hard rug.” They questioned the deployer’s change in proxy hours before the exploit. Forgiving wrote:

It was likely a pre-meditated planned rug

The community members are further suspicious as RocketSwap halted the mode of communications. There are also allegations that RocketSwap used to spoof the volumes.

With the RocketSwap exploit, some community members also point fingers at Coinbase Base due to multiple rug pull/hack incidents. 

On Aug. 1, another DEX on the Base network, LeetSwap, lost 340 ETH (approximately $600,000) due to a vulnerable function in the smart contract. Simultaneously, a scammer deployed a meme coin BALD on the Base network and later removed the liquidity, conducting a rug pull of over $23 million.

Following these incidents, a community member wrote:

“Base on-chain summer became base hard rug summer

Bald, leetswap, rocketswap and about 99% of contracts made on base.”

On Aug. 9, Coinbase launched the mainnet of its Layer 2 protocol Base. Within 24 hours, the network recorded over 136,000 daily active users. 

Community reactions. Source: X (Twitter)

Got something to say about the RocketSwap exploit or anything else? Write to us or join the discussion on our Telegram channel. You can also catch us on TikTok, Facebook, or X (Twitter).

For BeInCrypto’s latest Bitcoin (BTC) analysis, click here.

The post This Protocol on Coinbase’s Base Was Hacked Just 6 Days After Layer 2 Launch appeared first on BeInCrypto.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

UniLayer (LAYER) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0.1105
Капитализация $0 Rank 99999
Цена в час новости $ 0.1823 (-100%)

layer launch days protocol base coinbase hacked

layer launch → Результатов: 126


Shibarium Launch: Will It Impact the SHIB & BONE Price or Are We Staring at Another Bull Trap?

The much-anticipated launch of Shibarium, the Layer 2 scaling solution for the Shiba Inu (SHIB) project, has triggered intense speculation among cryptocurrency enthusiasts. While some see it as the long-awaited booster shot that will send SHIB to stratospheric levels, others foresee minimal, if any, impact on the token’s price.

2023-8-3 12:54


Фото:

Xandeum Announces Highly-Anticipated Launch on July 30

On July 30, 2023, at 11:00 a.m. Pacific Time, Xandeum, a groundbreaking blockchain firm dedicated to expediting humanity’s shift to decentralized power, will officially launch. By building a scalable, blockchain-based storage layer for smart contracts that adds a new dimension to the decentralized web, Xandeum’s goal is to enable collective self-determination by leveraging the power […]

2023-7-26 20:52


A16z’s mystery ‘orange ball’ revealed — new L2 rollup client ‘Magi’

Venture capital firm A16z revealed the secret behind its tweets that featured an orange ball – the launch of a new Layer 2 rollup client called Magi. Magi, a new rollup client developed in Rust — has been built on the OP Stack — a software stack specifically designed to create a blockchain dApp ecosystem […] The post A16z’s mystery ‘orange ball’ revealed — new L2 rollup client ‘Magi’ appeared first on CryptoSlate.

2023-4-19 22:53


Фото:

Myria Launches Its Native Token On OKX Exchange With A 45 Million MYRIA Airdrop

Myria, a decentralized Ethereum Layer 2 blockchain built to empower digital assets, NFT and blockchain gaming, has launched its native MYRIA token on the OKX crypto exchange. According to the team behind the project, the token launch brings numerous benefits to the community that will empower the growth of Web3. The team is planning a […]

2023-4-7 00:19


What Is Base? Coinbase’s L2 Network Explained

Coinbase’s Layer 2 Network: A Complete Guide Cryptocurrency exchange giant Coinbase has been making waves in the crypto industry with the launch of its Layer 2 network. This network is designed to enhance transaction speeds and reduce costs on blockchains like Bitcoin and Ethereum, making it an attractive proposition for developers and crypto enthusiasts alike.

2023-3-23 23:38