Thala recovers $25.5M in crypto lost through v1 farming vulnerability
Decentralized finance firm Thala Labs recovered $25.5 million of liquidity pool tokens stolen from one of its farming contracts after the hacker was tracked down by law enforcement and crypto sleuths.
In a post on Nov. 16, Thala revealed it had suffered a “security breach” on Nov. 15 due to an “isolated vulnerability” related to its v1 farming contracts, which allowed the hacker to withdraw liquidity tokens.
Thala said it immediately paused all relevant contracts and froze $11.5 million worth of Thala-related assets and was able to identify the hacker. “With the help of law enforcement, Seal 911, Ogle, and others, we were able to quickly identify the exploiter,” Thala said.
The hacker handed the funds back six hours after the incident, crypto sleuth Ogle said . Thala said it negotiated a $300,000 bounty with the hacker in exchange for the full return of user assets. Details of the attacker’s identity weren’t disclosed.
Thala stressed that “affected users require no further action, and positions will be made 100% whole.”
Source: Thala Labs
Access to Thala’s front end is live again. However, farming is still paused and users are unable to stake and unstake positions until Thala conducts an “extensive review” and re-audit of the protocol’s codebase.
“It’s inevitable some security issues may happen in the future on Move, but why we’re all building here is for these to occur at a far far less frequency and severity and trend to 0 over time as adjacent tooling gets stronger,” Thala’s CEO Adam Cader noted in a Nov. 16 X post.
Thala is one of the most prominent DeFi platforms on the Aptos layer-1 blockchain.
The THL token has tanked about 35% to $0.51 since the incident occurred, according to CoinGecko.
About $2.5 million worth of THL tokens were stolen in the exploit, while another $9 million came from Thala’s Move Dollar (MOD) stablecoin.
Related: M2 crypto exchange hacked for $13M, user funds already restored
Meanwhile, the total value locked on Thala fell from $240 million on Nov. 15 to $195.6 million at the time of writing, DefiLlama data shows.
Thala protocol’s change in TVL since April 2023. Source: DefiLlama
Almost $130 million was snatched from victims in October, with the bulk coming from exploits, blockchain security firm CertiK reported.
The biggest incident in October involved lending protocol Radiant Capital, which lost about $54 million.
About $460 million was stolen by hackers across 28 incidents in the preceding three months in Q3 2024, according to cybersecurity company Hacken.
Magazine: Meet the hackers who can help get your crypto life savings back
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
MARA's stock jumps after raising $1 billion via convertible notes to buy more bitcoin
MARA Holdings announced the successful closing of its $1 billion offering of 0% convertible senior notes due 2030.The bitcoin miner plans to allocate around $199 million of the proceeds to repurchase $212 million in principal of its existing convertible notes due 2026. The remaining funds will be used to acquire more bitcoin.
Gold loses luster as institutional demand fuels bitcoin price surge, analysts say
Bitcoin’s 46% surge over the past month, contrasted with gold’s 3% decline, highlights a shifting investor preference toward alternative store-of-value assets, analysts say.Derivatives traders are buying up bitcoin call options ahead of Trump’s inauguration, signaling strong bullish sentiment for the beginning of 2024.
SEC is 'engaging' Solana ETF applicants: report
SEC “engaging” on Solana ETF applications, sparking optimism for potential approval in 2025.VanEck, 21Shares, and Bitwise lead Solana ETF filings amid pro-crypto White House hopes.SOL token rises 4.6% to $247.91, bolstered by Solana’s strong DeFi ecosystem and demand.
Shiba Inu Developer Says SHIB Is No Longer a Memcoin