{"id":215318,"date":"2023-12-19T07:54:29","date_gmt":"2023-12-19T02:24:29","guid":{"rendered":"https:\/\/dripp.zone\/news\/?p=215318"},"modified":"2023-12-19T07:54:29","modified_gmt":"2023-12-19T02:24:29","slug":"hacker-steals-830000-from-cross-chain-bridge-of-solana-game-aurory-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/hacker-steals-830000-from-cross-chain-bridge-of-solana-game-aurory-crypto-news\/","title":{"rendered":"Hacker Steals $830,000 From Cross-Chain Bridge of Solana Game Aurory &#8211; Crypto News"},"content":{"rendered":"<p>Aurory purchased the stolen funds back from the hacker on a decentralized exchange<\/p>\n<div>\n<p>Aurory, a Solana-based Pokemon-inspired web3 game, lost around $830,000 worth of its native tokens to a bridge exploit.<\/p>\n<p>On Dec. 17, the project <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/AuroryProject\/status\/1736513600054006154\">reported<\/a> that a hacker had compromised the \u201cbuy endpoint\u201d for its Aurory Marketplace, allowing the attacker to increase their balance of AURY tokens in <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.aurory.io\/p\/syncspace-explained\">SyncSpace<\/a> \u2014 Aurory\u2019s \u201chybrid on-chain\/off-chain inventory system\u201d that also facilitates asset bridging between Solana and Arbitrum.<\/p>\n<p>The perpetrator behind the exploit was able to siphon 600,000 AURY (worth $830,000 at the time) from an Aurory team-controlled wallet. The tokens were moved to Arbitrum for sale via the Camelot decentralized exchange.<\/p>\n<p>Aurory responded by taking SyncSpace offline to patch the vulnerability, and used its market maker to purchase all of the stolen AURY. Liquidity for the AURY\/USDC pool on Camelot fell 80% from $1.5M amid the incident.<\/p>\n<p>\u201cThe exploiter does not have any more AURY left to sell,\u201d Aurory tweeted. \u201cWe swiftly moved to absorb sell pressure through our market maker and through pool rebalancing.\u201d<\/p>\n<p>Aurory emphasized that no user assets were impacted and there is no threat of further losses. The AURY token is down 20% since the exploit began, according to CoinGecko.<\/p>\n<p>Aurory said it will restore SyncSwap functionality \u201cin the coming days\u201d after the vulnerability has been patched. The exploit occurred despite Aurory previously engaging Ottersec, a web3 security firm, for code auditing. Aurory <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.aurory.io\/p\/aurorys-cross-platform-journey-begins\">integrated<\/a> support for Arbitrum via SyncSpace in July.<\/p>\n<p>Cross-chain bridges have proved to be a pervasive risk within the web3 ecosystem. According to Rekt, four of the five largest DeFi exploits targeted bridges, with Ronin, Poly Network, BNB Bridge, and Wormhole losing more than<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/rekt.news\/leaderboard\/\"> $2.1B<\/a> in assets combined.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Aurory purchased the stolen funds back from the hacker on a decentralized exchange Aurory, a Solana-based Pokemon-inspired web3 game, lost around $830,000 worth of its native tokens to a bridge exploit. On Dec. 17, the project reported that a hacker had compromised the \u201cbuy endpoint\u201d for its Aurory Marketplace, allowing the attacker to increase their [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":215319,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[274,273,272,244,266,271,268,270,269,267],"class_list":["post-215318","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-de-fi","tag-crypto-finance","tag-decentralized-finance","tag-liquidity","tag-metamask","tag-pancake","tag-slippage","tag-sushiswap","tag-tronlink","tag-trust-wallet","tag-uniswap"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/215318","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=215318"}],"version-history":[{"count":2,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/215318\/revisions"}],"predecessor-version":[{"id":215324,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/215318\/revisions\/215324"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/215319"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=215318"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=215318"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=215318"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}