Exchange Profile picture
Feb 5 12 tweets 2 min read
We’ve been baptised - we experienced our first hack. Read on
1/12
02:30 UTC: Our team detected some suspicious activity on the main platform.
2/12
03:45 UTC: After internal investigations from our US-based colleagues, the core team was gathered together and an emergency situation room was established.
3/12
We shortly identified the issue: a malicious party was able to drain all the SOL locked in the accounts that were part of open offers.
4/12
NFTs listed for sale or auction were safe. The attacker was only able to abuse the offer flow. A total of 427 offers were drained (pertaining to a couple of hundreds of different users)
5/12
04:30 UTC: We temporarily disabled the ‘making’ and ‘accepting offers’ features, both at the contract level and from the UI.
6/12
5:00 UTC: We decided to lock in and purchase enough SOL in order to secure refunds for everyone affected (~1k SOL).
7/12
7:15 UTC: We refunded everybody that we identified was a victim in the attack.
8/12
We’ve already identified the issue causing this, and we will be securing our contract to eliminate this vulnerability. Until this is done, the ‘make an offer’/’accept an offer’ flows will remain locked.
9/12
If you think you have been part of this attack, please check this file that contains details about the offers that have been affected, plus the refunding transactions which we issued (originating wallet 4rZ3GqA4bniVJB9TCaiUV8Q8suCpdkjexXmANUMT6tGX
)
cdn.exchange.art/refunds-5-feb-…
10/12
If you think we have missed you and you are owed a refund, please reach out to our support desk, and we will be happy to reimburse your made offer.
11/12
We take our commitment to the 1/1 artists and our community very seriously. We are making all the efforts to strengthen the fort and grow together. Thanks for your support.
12/12

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Exchange

Exchange Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

:(