1/ At $50m The @CashioApp exploit was the 2nd largest heist on @solana & 13th largest hack overall. Despite this its been radio silence for hours.
@Saber_HQ have been working on it but have not been contacted by the exploiter.
Can anyone help? What we know & some thoughts🧵👇
2/ After the exploiter minted 2billion CASH they drained the CASH deposits of USDT & USDC ($26m) & swapped their remaining CASH tokens for ($25m) through @Saber_HQ crashing CASH's price to 0.
They now had~$50m of USDC/USDT/UST, $21m of which was swapped to ETH & wormholed to ETH
3/ All this was detailed by @0xavarek in this detailed thread:
The attacker's SOL wallet was funded by @sideshiftai a non-KYC dex who could potentially help but have been mostly silent on twitter.
4/ So what now?
The @CashioApp team's updates have been worryingly sporadic.
@Saber_HQ has been involved in the investigation too as they were in the process of investing in Cashio & heavily endorsed CASH on its platform.
They have been working with exchanges & law enforcement
5/ @Saber_HQ member Ian Macalinao personally audited the code & noted that the team did not audit Cashio as closely as they should have, having heavily endorsed them.
6/ @Saber_HQ is one of @solana's main defi protocols and a key building block for stables & liquidity. Most community members would not have been liquidity providing CASH had it not been one of the key tokens of the Saber platform, endorsed and audited.
7/ A great deal of people have been affected. Funds taken were their savings, money hard-earned & in some cases a large proportion of their livelihoods.
There has been no contact with the attacker, but hopefully we can find a solution that minimizes harm & suits all parties.
8/ Investors definitely bear the risk & learned hard lessons. Decentralization means these risks can have irreversible outcomes.
Still, it hits different when it happens to you. I have spent time speaking to victims and the anguish, mental impact & anxiety is crushing.
9/ Personally, I have been heavily affected by this, having moved a very large amount of borrowed stables into CASH-USDC to farm a few days back. It is all now lost. A painful lesson in risk management.
I am not a good place, but I hope we get some resolution regardless.
10/ For now some of @Saber_HQ's investors @RaceCapital (@maccanatron) @multicoincap (@KyleSamani) have helped put Saber in contact with those who can help but remained distanced which may be fair given they appear removed from Cashio.
Hopefully we can find a suitable outcome with the exploiter. There haven't been many updates or a post-mortem released yet but perhaps this is normal given the situation is fluid.
Ultimately the investors & community will likely have to bear responsibility of the risks taken.
But, failing any solution with the exploiter there is hope that @Saber_HQ & its backers would step in to help minimize the damage to investors / community & restore confidence in Solana's leading cross-chain stablecoin exchange.
2/ .. & they both just used that exchange to fund their activities
It's been 24 hours later and not much has emerged or been announced. There are many anxious investors in the Cashio, Saber & Sunny discords.
3/ Spreading risk is impt. Unfortunately in this instance many people have lost a large amount of USD (some upwards of millions) & it has been difficult for many to stay calm.
The hacker sent back amounts <$100k but not directly to user wallets (to LP-related side wallets)
In the last hour 100+ @DegenTrashPanda have been swept, raising the floor from 2.6◎ to 3◎. As you know, DTP is the companion Degeniverse project to @DegenApeAcademy.
Some observations & upcoming catalysts around the DTP game & $RAIN token 🦝💦🧵👇 #solana#solananfts#nfts
Over the last hour, wallet 8igPE has picked up over 100 Degen Trash Pandas. This is a different individual to the ones that bought 26 Degen Apes overnight.
8igPE holds 244 DTP as of writing along with 6 Panda Rugs & 84 Degen Apes - a big believer in the Degeniverse while also owning various other Solana NFTs like @TaiyoRobotics@SolanaMBS & @catalinawhales
A little bit of action this evening on the @DegenApeAcademy front with 26 apes being sold in quick succession over the last 3 hours to GMos & 10 individual buyers, bringing the floor to 58SOL🧵👇 #solana#solananfts#nfts#degenape
The ape buying was kicked off by wallet GMos 3 hours ago - with it buying 16 apes and transferring them to 2T5k, an account that holds $1.08m worth of @genopets GENE tokens & 24 @Gyris_official NFTs. nfteyez.global/accounts/2T5kb…
Since then there have been another 10 sales mostly on @MagicEden in the 55 to 65 SOL range.
All of these went to 10 different buyers, with the pink lady sailor heading @9x9x9eth's way.
Here's what you need to know about the X'mas❤️mini-game + the innovations this project is pioneering🧵👇#nftcommunity
People who minted DTPs before the pause would have noticed ❤️ traits with a # from 1 to 6 applied to their panda.
This was part of a minigame @pit_the_panda has created for X'mas. In typical Pit / Joker style, he kept us guessing on its objective.
The aim of the game was to reward those who held their pandas longest without moving or listing them. Every snapshot if they had not been moved the ❤️ # decreased, with the aim being to get to 1❤️
The lower the ❤️ #, the greater the chance for your Panda to get an X'mas outfit!