Hacker Of Solana Based Cashio Will Return Part Of Stolen Funds

BitcoinistPublished on 2022-03-29Last updated on 2022-03-29

Abstract

The team behind Cashio, a Solana-based dApp that was hacked last week, published a postmortem report on the attack. In...

The team behind Cashio, a Solana-based dApp that was hacked last week, published a postmortem report on the attack. In one of the biggest hacks on this network, the bad actors managed to steal $50 million by exploiting a vulnerability on the dApp.
As Bitcoinist reported, to use Cashio, users need to mint CASH by making SABER deposits on the USDT-USDC pool. Saber operates as a cross-chain AMM for Solana-based stablecoins.
The bad actor apparently exploited a point of failure on Cashio’s account validation system. This security component was incomplete and enable the bad actor to create multiple accounts.
The report from Saber Labs records an increase in activity for the CASH pools. Thus, there was more capital locked on Cashio than usual, probably making it more attractive for the bad actors.
The team at Saber Labs claimed it took measures to prevent something similar from happening in the future. In particular, they will be more transparent with their code reviewing and auditing process.
Any product on the Saber ecosystem, they announced, will be reviewed to guarantee the safety of the funds. This measure will not apply to closed source protocol which, Saber Labs believes, “have the benefit of being much harder to hack”.
Saber Labs apologized for the attack on its users. They claimed to lack the funds to “payback depositors”, or to economically amend this “catastrophic” event to Saber users.
The team made the following announcement in an attempt to revert a situation that they believe could negatively impact its users:
If you are the hacker and are reading this, we hope you will consider returning the funds rather than donating them to charity: accounts with over $100k are often users’ life savings on leverage, and many of us will seriously be affected financially after this incident. We are willing to give $1M of USDC as a bounty if the funds are returned.
Solana dApp Hacker Pulls A Robinhood
This plead was apparently listened to and replied to for the benefit of Cashio users. According to a pseudonym user, the bad actors decided to return the funds to those with accounts that lost under $100,000 in CASH.
In order to get their funds back, users need to access the following link. This will lead them to an open-source platform created to receive refunds submissions.
The creator of this website published the Github link to the open-source code that supports the refund submission platform. Thus, anyone can verify its authenticity and should check for any potential vulnerabilities or malicious code.
The attacker or attacker left the following message on their actions:
The intention (with the Cashio hack) was only to take money from those who do not need it, not from those who do. Will be using the th gains to return more funds to those affected, even some accounts more than 100k. Will not return funds to accounts that already receive refund.
The attacker made several demands, including potential leaders for the organization backing the Solana dApp.
Thanks @wireless_anon for setting this up. We have deployed the same code at https://t.co/i4KtrqfB8E
We will send out a tutorial on how to use this and how to verify you entered everything correctly soon, as well as more information on how to submit the signatures to us after. https://t.co/RncwVBCmfE
— Cashio ($CASH) 💵 (@CashioApp) March 28, 2022
At the time of writing, Solana (SOL) trades at $112 with a 1% profit on the 4-hour chart.

Solana SOL SOLUSDT

SOL with moderate profits on the 4-hour chart. Source: SOLUSDT Tradingview

Related Reads

The Real Battlefield of AI Lies in the 'Dark Forest'

The article "AI's Real Battlefield is in the 'Dark Forest'" discusses the shifting dynamics in the global AI landscape, contrasting the strategic directions of Chinese and U.S. AI developers. Chinese companies like Alibaba (with its "HappyHorse" video model), ByteDance (Seedance 2.0), and Kuaishou (Kling 3.0) have taken the lead in text-to-video generation, surpassing OpenAI’s now-discontinued Sora. These models are deeply integrated into their parent companies’ content ecosystems (e.g., Douyin, Kuaishou), serving to reduce content creation costs and enhance user engagement rather than operating as standalone profit centers. In contrast, U.S. firms are pivoting toward high-stakes enterprise and security applications. Anthropic’s Claude Mythos model demonstrates advanced capabilities in autonomously discovering and exploiting software vulnerabilities, prompting concern at the highest levels of U.S. financial and governmental institutions. OpenAI responded with its own GPT-5.4-Cyber, signaling a strategic shift from consumer-facing products to enterprise-grade tools focused on cybersecurity and programming. The divergence is attributed to fundamental differences in resources and market structures. U.S. companies, backed by vast computational resources (e.g., Amazon and Google supply Anthropic with substantial funding and TPU access), can pursue deep, specialized R&D in high-value B2B sectors. Chinese firms, facing significant compute power constraints and a less mature enterprise SaaS market, have found success by leveraging their massive consumer platforms and optimizing for cost-efficiency. The article warns that the AI race is entering a "dark forest" phase—a reference to competitive dynamics where cybersecurity capabilities could determine digital sovereignty. While Chinese models like Zhipu AI’s GLM-5.1 show promise in narrowing the gap in coding proficiency, the author stresses that achieving parity in security-critical AI will require asymmetric strategies, including greater investment in coding models, adaptation to domestic hardware, and exploring international markets in the Global South.

marsbit5m ago

The Real Battlefield of AI Lies in the 'Dark Forest'

marsbit5m ago

Trading

Spot
Futures
活动图片