[ad_1] <br><div> <p>Hedera, the staff behind distributed ledger Hedera Hashgraph, has confirmed a sensible contract exploit on the Hedera Mainnet that has led to the theft of a number of liquidity pool tokens.</p><p>Hedera stated the attacker focused liquidity pool tokens on decentralized exchanges (DEXs) that derived its code from Uniswap v2 on Ethereum, which was ported over to be used on the Hedera Token Service.</p><amp-twitter height="694" width="486" layout="responsive" data-tweetid="1634055353435561986?ref_src=twsrc%5Etfw"/> <p>The Hedera staff defined that the suspicious exercise was detected when the attacker tried to maneuver the stolen tokens throughout the Hashport bridge, which consisted of liquidity pool tokens on SaucerSwap, Pangolin and HeliSwap. Operators acted promptly to briefly pause the bridge.</p><p>Hedera didn’t verify the quantity of tokens that had been stolen.</p><p>On Feb. 3, Hedera <a target="_blank" href="https://hedera.com/blog/hedera-hashgraph-announces-mainnet-launch-of-evm-compatible-smart-contracts-2-0" rel="noopener nofollow" data-vars-outbound-link="https://hedera.com/blog/hedera-hashgraph-announces-mainnet-launch-of-evm-compatible-smart-contracts-2-0">upgraded</a> the community to transform Ethereum Digital Machine (EVM)-compatible sensible contract code onto the Hedera Token Service (HTS).</p><p>A part of this course of includes the decompiling of Ethereum contract bytecode to the HTS, which is the place <a target="_blank" href="https://cointelegraph.com/press-releases/tangent-finance-to-launch-the-first-dex-on-hedera-hashgraph/amp" data-amp="https://cointelegraph-com.cdn.ampproject.org/c/s/cointelegraph.com/press-releases/tangent-finance-to-launch-the-first-dex-on-hedera-hashgraph/amp" rel="noopener">Hedera-based DEX</a> SaucerSwap <a target="_blank" href="https://twitter.com/SaucerSwapLabs/status/1633796307289505793" rel="noopener nofollow" data-vars-outbound-link="https://twitter.com/SaucerSwapLabs/status/1633796307289505793">believes</a> the assault vector got here from. Nonetheless, Hedera didn’t verify this in its most up-to-date publish.</p><p>Earlier, Hedera managed to close down community entry by turning off IP proxies on March 9. The staff stated it has recognized the “root trigger” of the exploit and is “engaged on an answer.”</p><amp-twitter height="694" width="486" layout="responsive" data-tweetid="1634055363069906945?ref_src=twsrc%5Etfw"/> <p>"As soon as the answer is prepared, Hedera Council members will signal transactions to approve the deployment of up to date code on mainnet to take away this vulnerability, at which level the mainnet proxies shall be turned again on, permitting regular exercise to renew," the staff added.</p><figure><amp-img src="https://s3.cointelegraph.com/uploads/2023-03/f87e39f5-c25f-413a-adab-b03e52178fa3.jpg" alt="" title="" width="4" height="3" layout="responsive"/><figcaption class="inline-style-0"><em>A discover posted by Hedera on its standing webpage cautioned customers that its community wouldn't be accessible. Supply: </em><em>Hedera</em></figcaption></figure><p>Since Hedera turned off proxies shortly after it discovered the potential exploit, the staff <a target="_blank" href="https://twitter.com/hedera/status/1633984384067076097" rel="noopener nofollow" data-vars-outbound-link="https://twitter.com/hedera/status/1633984384067076097">suggested</a> tokenholders examine the balances on their account ID and Ethereum Digital Machine (EVM) deal with on hashscan.io for their very own “consolation.”</p><amp-twitter height="694" width="486" layout="responsive" data-tweetid="1633926334920392713?ref_src=twsrc%5Etfw"/> <p><strong><em>Associated: </em></strong><a target="_blank" href="https://cointelegraph.com/news/hedera-governing-council-to-buy-hashgraph-ip-and-open-source-projects-code/amp" data-amp="https://cointelegraph-com.cdn.ampproject.org/c/s/cointelegraph.com/news/hedera-governing-council-to-buy-hashgraph-ip-and-open-source-projects-code/amp" rel="noopener"><strong><em>Hedera Governing Council to buy hashgraph IP and open-source project’s code</em></strong></a></p><p>The value of the community’s token Hedera (<a target="_blank" href="https://cointelegraph.com/hedera-hbar-price-index" rel="noopener">HBAR</a>) has fallen 7% for the reason that incident roughly 16 hours in the past, consistent with the <a target="_blank" href="https://cointelegraph.com/news/why-is-the-crypto-market-down-today/amp" data-amp="https://cointelegraph-com.cdn.ampproject.org/c/s/cointelegraph.com/news/why-is-the-crypto-market-down-today/amp" rel="noopener">broader market fall over the last 24 hours. </a></p><p>Nonetheless, the overall worth locked (TVL) on SaucerSwap fell practically 30% from $20.7 million to $14.58 million over the identical timeframe:</p><figure><amp-img src="https://s3.cointelegraph.com/uploads/2023-03/67c3202f-21b3-407b-9100-199fee53f8d0.jpg" alt="" title="" width="4" height="3" layout="responsive"/><figcaption class="inline-style-0"><em>The TVL on SaucerSwap fell sharply following the information of the exploit. Supply: </em><em>DefiLlama</em></figcaption></figure><p>The autumn suggests a major quantity of tokenholders acted shortly and withdraw their funds following the preliminary dialogue of a possible exploit.</p><p>The incident has probably spoiled a significant milestone for the community, with the <a target="_blank" href="https://cointelegraph.com/news/hedera-hashgraph-launches-mainnet-open-beta-and-token-distribution/amp" data-amp="https://cointelegraph-com.cdn.ampproject.org/c/s/cointelegraph.com/news/hedera-hashgraph-launches-mainnet-open-beta-and-token-distribution/amp" rel="noopener">Hedera Mainnet</a> surpassing 5 billion transactions on March 9.</p><amp-twitter height="694" width="486" layout="responsive" data-tweetid="1633604447262654465?ref_src=twsrc%5Etfw"/> <p>This seems to be the primary reported community exploit on Hedera because it was launched in July 2017.</p> </div><script async src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <br>[ad_2] <br><a href="https://cointelegraph.com/news/hedera-confirms-exploit-on-mainnet-led-to-theft-of-service-tokens/amp">Source link </a>
Hedera confirms exploit on mainnet led to theft of service tokens
[ad_1] Hedera, the staff behind distributed ledger Hedera Hashgraph, has confirmed a sensible contract exploit on the Hedera Mainnet that has led to the theft of a number of liquidity pool tokens.Hedera stated the attacker focused liquidity pool tokens on decentralized exchanges (DEXs) that derived its code from Uniswap v2 on Ethereum, which was ported over to be used on the Hedera Token Service. The Hedera staff defined that the suspicious exercise was detected when the attacker tried to maneuver the stolen tokens throughout the Hashport bridge, which consisted of liquidity pool tokens on Sau