Duo Behind $9M Platypus Exploit Acquitted by Paris Court: Report

CoinDeskPolicyPubblicato 2023-12-03Pubblicato ultima volta 2023-12-04

Introduzione

Charges were dropped after one of the accused argued he was an "ethical hacker," according to French news publication Le Monde.

Two men involved in an attack on decentralized finance (DeFi) protocol Platypus were acquitted by a Paris court, French news publication Le Monde reported Friday.

The duo was arrested in February over the exploit, which saw $9 million worth of crypto stolen. Later that month, Platypus recovered some of that sum and said it intended to return at least 63% of the funds to users.

8.8K
Former Binance CEO CZ Is Stuck in U.S. for Now; Animoca Brands Invests in TON Network

The court found that the exploiters acted in good faith, according to the report, after one of them – identified by Le Monde as Mohammed M – argued that he was an "ethical hacker" who was taking the "endangered funds" so he could return them to the protocol later. The report said he'd hoped to get a bonus of 10% of the total sum taken from the company.

Advertisement
Advertisement

The court reportedly dropped the charges of money laundering and receiving stolen funds as the criminal charges did not hold up in court. Platypus can still pursue charges against the suspects in the civil court, the court said.

CoinDesk has reached out to Platypus for comment.

Edited by Sandali Handagama.

Letture associate

An Open-Source AI Tool That No One Saw Predicted Kelp DAO's $292 Million Vulnerability 12 Days Ago

An open-source AI security tool flagged critical risks in Kelp DAO’s cross-chain architecture 12 days before a $292 million exploit on April 18, 2026—the largest DeFi incident of the year. The vulnerability was not in the smart contracts but in the configuration of LayerZero’s cross-chain bridge: a 1-of-1 Decentralized Verifier Network (DVN) setup allowed an attacker to forge cross-chain messages with a single compromised node. The tool, which performs AI-assisted architectural risk assessments using public data, identified several unremediated risks, including opaque DVN configuration, single-point-of-failure across 16 chains, unverified cross-chain governance controls, and similarities to historical bridge attacks like Ronin and Harmony. It also noted the absence of an insurance pool, which amplified losses as Aave and other protocols absorbed nearly $300M in bad debt. The attack unfolded over 46 minutes: the attacker minted 116,500 rsETH on Ethereum via a fraudulent message, used it as collateral to borrow WETH on lending platforms, and laundered funds through Tornado Cash. While an emergency pause prevented two subsequent attacks worth ~$200M, the damage was severe. The tool’s report, committed to GitHub on April 6, scored Kelp DAO a medium-risk 72/100—later acknowledged as too lenient. It failed to query on-chain DVN configurations or initiate private disclosure, highlighting gaps in current DeFi security approaches that focus on code audits but miss config-level and governance risks. The incident underscores the need for independent, AI-powered risk assessment tools that evaluate protocol architecture, not just code.

marsbit12 min fa

An Open-Source AI Tool That No One Saw Predicted Kelp DAO's $292 Million Vulnerability 12 Days Ago

marsbit12 min fa

Trading

Spot
Futures
活动图片