Optimism Foundation sends $20M to the wrong wallet – OP drops 36%

cryptoslate发布于2022-06-09更新于2022-06-09

文章摘要

The Optimism Foundation has issued a statement confirming that 20M OP tokens meant for a liquidity provisioning partner have been sent to the wrong address.

The Optimism Foundation has issued a statement confirming that 20M OP tokens meant for a liquidity provisioning partner have been sent to the wrong address. The price of the OP token dropped from $1.12 on June 8 to just $0.70 after the news broke. The statement read,

“The Optimism Foundation engaged Wintermute for liquidity provisioning services … a temporary grant of 20 million OP tokens was allocated to Wintermute from the Foundation’s Partner Fund.
Wintermute provided an address to receive the borrowed tokens. The Optimism Foundation sent two separate test transactions, and upon Wintermute’s confirmation for each, sent the rest. Unfortunately, Wintermute later discovered they could not access these tokens because they had provided an address for an Ethereum (L1) multisig that they had not yet deployed to Optimism (L2).”

The very partner hired to help facilitate liquidity services was not using the product Optimism had hired them to support. Although Wintermute claims to be a “leading global algorithmic market maker in digital assets”, it has made what can be considered a fundamental mistake in crypto, especially for an algorithmic market maker.

In recompense, Wintermute has:

“committed to buying back the tokens lost. They will monitor the address that holds these lost tokens and buy as the address sells.”

Recovery process

Optimism stated that Wintermute had attempted to resolve the situation without the need to repurchase the tokens as they “began a recovery operation with the goal to deploy the L1 multisig contract to the same address on L2.” However, Optimism claims:

“an attacker was able to deploy the multisig to L2 with different initialization parameters before these efforts were completed, assuming ownership of the 20m OP.”

With that mistake, Wintermute essentially left 20 million OP tokens out on the street for anyone to pick up by deploying an Optimism L2 contract to the address. So, it could be seen as a PR move to refer to the new owner as an “attacker;” putting in question the validity of the “exploit” or “hack”. Optimism has since reported that 1 million OP has been sold from the wallet.

Whoever obtained access to the wallet has undoubtedly made an ethically grey move by exploiting the ineptitude of an automated market maker. However, Wintermute’s recent statement suggests there was more to the situation than a simple, smart contract deployment.

Wintermute response

Wintermute wrote a response to the Optimism community via its governance forum. In it, the team explained:

“as we communicated the wallet address to the Optimism team, we made a serious error. We had a Gnosis safe deployed on mainnet for a while and due to an internal mistake, we’ve communicated the very same wallet as the receiving address.”

The post confirmed that this was “not a smart thing to do.” However, it appears that this happened on May 30, the day before the mainnet launch for Optimism.

Wintermute then took possession of a further 20 million OP by “providing $50 million USDC as collateral.” However, a third party was faster than Wintermute in retrieving the funds, the “attacker,”:

“proceeded with performing a replay attack by replaying the Gnosis Safe MasterCopy 1.1.1 deployment from Eth mainnet. They then used the previously deployed contract 0xE714… to deploy vaults per batches of 162.”

Wintermute then explained a complicated method used by the external third party to access the funds was through a Tornado Cash deposit. The depiction indeed gives the impression that a complex attack took place.

Indeed, Wintermute praised the attack stating, “the attack has been performed has been rather impressive” before even offering them “consulting opportunities” if they return the funds.

In the face of a highly embarrassing situation, the crypto community is not all buying the story; Bear Baron Hellspawn said:

“Either amateur hour by so-called “liquidity provider”
Either inside job. Because unless you do some voodoo sh*t you cannot assume that $OP tokens will be transferred at a very SPECIFIC address.”

Wintermute ended its statement with a threat to the “attacker” stating,

“we are 100% committed to returning all the funds, tracking the person(s) responsible for the exploit, fully doxxing them and delivering them to the corresponding juridical system. Remember that robbers need to get lucky every time. Cops only have to get lucky once.”

Wintermute is currently at Consensus 2022 in Texas, starting June 9. CryptoSlate reached out to both the CEO and COO, but no response was received at the time of publishing.

你可能也喜欢

交易

现货
合约

热门文章

如何购买OP

欢迎来到HTX.com!我们已经让购买Optimism(OP)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Optimism(OP)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Optimism(OP)购买完您的Optimism(OP)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Optimism(OP)在HTX的现货市场轻松交易Optimism(OP)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

1.4k人学过发布于 2024.03.29更新于 2026.06.02

如何购买OP

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对OP(OP)币价的意见。

活动图片