The Velocore DEX was exploited. Our teams have been employing our ecosystem security measures to mitigate the damage from this attack. More info in this thread.
Linea network remains secure, this only affected a 3rd party dapp.
@hexagate_ alerted us about the ongoing exploit, helped trace stolen user funds, exploiter addresses and vulnerable contracts. 700ETH moved off Linea via a 3rd party bridge. It was the middle of the night, Velocore was still vulnerable and we could not get ahold of their team.
Because other avenues of handling this exploit closed, our team halted the sequencer to prevent additional funds bridging out. This was the last resort action to protect users on Linea.
The sequencer was paused from block 5081800 and 5081801.
During this pause, we gave the @Velocorexyz time team to support their efforts of triaging the vulnerability.
We also censored the hacker's addresses. This significantly reduced the ecosystem impact on Linea users.
Linea's team made a decision to halt block production by pausing the sequencer and censor attacker addresses to protect the users and builders in our ecosystem. Like other L2s, we are still in the "training wheels" phase of existence, giving us safeguards to use.
One of the key drivers in our decision to pause the sequencer was that the hacker had acquired and was beginning to sell a large sum of tokens into ETH. This would have created other issues in the ecosystem for users beyond the liquidity pool draining exploit.
Linea's goal is to decentralize our network - including the sequencer. When our network matures to a decentralized, censorship-resistant environment, Linea's team will no longer have the ability to halt block production and censor addresses - this is a primary goal of our network
Most L2s, including Linea, still rely on centralized technical operations which can be leveraged to protect ecosystem participants. Linea's core value is a permissionless, censorship-resistant environment so it was not a decision we took lightly.
Meanwhile, teams at Velocore and Linea have requested to CEX to freeze the exploited funds, and Velocore is setting up an onchain negotiation process.
The Velocore team has just released a post-mortem on the exploit.
• All volatile pools(CPMM) in Linea and zkSyncEra Velocore are affected.
• No stable pools are affected.
• Team is pursuing onchain negotiations, CEX freezes, and compensating users
Despite undergoing multiple audits, Velocore's protocol still had a exploitable flaw. We are grateful to the ecosystem security partners @hexagate @Cyvers_ and @HypernativeLabs for the fast response to assist @velocorexyz
User security is a top priority for Linea, which is why we have developed our ecosystem-wide threat monitoring and prevention mechanisms which went into full action on this exploit. We'll continue working closely with the Velocore team and supporting them in their next steps.
• • •
Missing some Tweet in this thread? You can try to
force a refresh
Linea Surge is a points-driven program that provides you with LXP-L tokens for having assets #OnLinea and deploying it into DeFi protocols on the network.
Linea Surge will run for 6 Volts (6 months), or until we reach $3b in TVL.⚡️
Linea Volt 1 is the perfect time to jump in and collect the biggest boost!🔋
LXP-L distributed for liquidity will decrease by 10% at every Volt, therefore to maximize your liquidity contribution, you should consider bridging to Linea in Volt 1.
The team is working to make the LXP mint happen soon. Here's why it's taking longer than normal, and how our extra efforts are geared to protect the interests of our community.
1. Thanks to the community, we detected Sybil activity which managed to bypass issuers and attain attestations as though they are individual people. We strive to make our Voyage human-centric, so this caused us to pause distributing LXP
2. Since LXP is a non transferable token, ensuring it goes to authentic people is a key focus before we mint. We are cooking on this.
Here’s our plan regarding the implementation of Dencun (EIP-4844) on Linea Mainnet. ❤️
Our target is to launch the upgrade on March 26th. In this thread, we’ll share more details about this target date and how it fits into the other things going on in the ecosystem.
🧵
Our engineers and auditors have been working on EIP-4844 as the sole focus since we launched our Alpha v2, an upgrade which resulted in 66% lower fees for the community.
With Alpha v2 and 4844, Linea will be well-positioned to offer very cheap gas prices.🔥
Right now, we’re engaged with Tier 1 security vendors to audit the changes to our smart contracts. When this audit is complete, the testnet is running smoothly and we are confident that our users are protected, we’ll be able to implement the change. We’re in the last steps.
🧵Human verification has arrived!
From now until the end of the DeFi Voyage, Voyagers can execute proof of humanity with our attestation providers on .
But first, let’s learn about on-chain attestations & digital identity with platforms like Verax. ⛓️ intract.io/linea
👥 An attestation simply means proof or evidence.
Passport: proof of citizenship; Degree: proof of educational credentials.
In Web3, attestations represent digital identity, ownership and more. They are the foundation blocks adding to the excitement of blockchain tech! 🌎🔐
🚀 Enter Verax, an on-chain registry. It is a collaborative project with @Consensys, @Clique2046, @karma3labs, @aspecta_id, @padolabs, & @protocolreclaim on board. @gitcoin and many others are integrating with this system, crafting a robust network of attestations! 🌳
In preparation, we wanted to go through some crucial consideration points👇🧵
Remember: Linea Voyage XP (LXP) are NON-TRANSFERABLE⚠️
This means that once LXP are collected in a wallet account, they cannot be moved. It is therefore crucial to accumulate LXP in one wallet to accurately measure your contribution to the growth of the Linea network.
✴️How does POH work?
LXP can only be minted on accounts that can prove human ownership. This is done by examining your account’s historical data across multiple chains.
Users will be able to carry out POH through identity partners once the POH wave is launched.