Arcadia is backed by Coinbase Ventures. The project acknowledged the hack, encouraging users to revoke permissions.
Arcadia Finance exploited for $3.5 million
MoonPay apparently gets scammed out of a $250,000 donation to Trump inaugural fund
As it happens, "Ivan & Mouna" match the names of MoonPay CEO Ivan Soto-Wright and CFO Mouna Siala. The crypto address used to send the transaction also appears to be one of MoonPay's company crypto wallets.
MoonPay had told Fox Business shortly before the transaction that they intended to contribute an undisclosed amount to the Trump inaugural fund.
Only weeks after the botched donation, MoonPay was selected as a payment processor for Trump's $TRUMP memecoin.
- "The DOJ Seemingly Outed Top Crypto Executives as Falling for a Nigerian Crypto Scam", NOTUS [archive]
- Complaint in US v. Approximately 40,353 USDT.ETH Cryptocurrency [archive]
Kinto token crashes; community claims rug pull, Kinto claims hack
However, Kinto blamed the token crash on the exploit that was recently disclosed by VennBuild, claiming on Twitter that "we got hacked by a state actor". Venn seemed to corroborate Kinto's explanation that the crash was related to the exploit, tweeting that although they had tried to warn all vulnerable projects before publicly disclosing the bug, "Sadly the Kinto token was not found despite being vulnerable, and exploited without time to mitigate."
Kinto has announced a plan to try to fundraise to cover a $1.4 million loss in liquidity, then create a new $K token based on a snapshot of previous token holdings.
$2.2 million in user funds stolen from Texture; hacker returns 90%
Shortly after the attack, Texture sent a message to the thief: "We are offering a 10% bounty of any funds stolen, which are yours to keep if you return the remaining 90%. You made an opsec mistake, but it’s not too late to avoid escalating the situation."
The threat and "bounty" offer apparently worked, and the hacker returned $1.98 million, keeping $220,000 as a so-called "greyhat bounty". "As the hacker has fulfilled their side of the agreement, we will not pursue the matter further," wrote Texture.
Security researchers disclose exploit that put over $10 million across multiple protocols at risk
According to the researchers, they found thousands of contracts affected by the exploit, and worked with multiple protocols to upgrade contracts or withdraw vulnerable funds. The researchers theorized that the attackers were "likely a sophisticated group waiting for a bigger target, not small wins."
GMX exchange hacked for $42 million
GMX offered a 10% "bug bounty" to the hacker if they returned the funds. The attacker later returned $40.5 million in stolen assets; unusually, this is more than the 90% return requested by GMX.
Resupply stablecoin lender exploited for $9.3 million
Resupply announced the theft shortly afterwards, and stated that they had paused the vulnerable contract.
Resupply is a fairly new project, having officially launched on March 20 — about three months before the exploit.
Self Chain fires founder after $50 million scam allegations
Aza Ventures was initially hesitant to name the scammer, hoping they could pressure the scammer to return the stolen funds, but later reports quickly named Self Chain founder Ravindra Kumar as the alleged culprit. Kumar posted on June 19, "I've been accused of serious wrongdoing, which is completely false."
On June 23, Self Chain announced that they had terminated Kumar as CEO "due to recent developments that diverge from the founding vision".
New York scammer "daytwo" steals $4 million from Coinbase users, blows most of it gambling
zachxbt noted that Nieves seems to have a gambling problem, depositing much of the stolen funds into crypto gambling websites. "You’ll see onchain how casino deposits get smaller as he loses funds," wrote zachxbt. "Recently this escalated to the point where he started stealing cuts from accomplices." He also appears to have used some of the stolen funds on luxury goods, including a Corvette and expensive watches.
- Tweet thread by zachxbt [archive]