{"id":257057,"date":"2024-03-01T10:33:22","date_gmt":"2024-03-01T05:03:22","guid":{"rendered":"https:\/\/dripp.zone\/news\/?p=257057"},"modified":"2024-03-01T10:33:22","modified_gmt":"2024-03-01T05:03:22","slug":"seneca-recovers-80-of-funds-after-6-4m-exploit-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/seneca-recovers-80-of-funds-after-6-4m-exploit-crypto-news\/","title":{"rendered":"Seneca Recovers 80% of Funds After $6.4M Exploit &#8211; Crypto News"},"content":{"rendered":"<p><\/p>\n<div>\n<p>The Seneca Protocol hacker has given back $5.3 million worth of Ether tokens after draining $6.4 million on Ethereum and Arbitrum networks. Initial investigations suggested that an approval mechanism bug in the protocol\u2019s smart contract was exploited.<\/p>\n<p>The stablecoin protocol had recently confirmed roping in with law enforcement but offered leniency, stating the team wouldn\u2019t take legal steps if the hacker returned 80% of the funds, keeping 20% as a reward.<\/p>\n<h2>Seneca Hacker Returns 80% of Stolen Funds<\/h2>\n<p>The vulnerability <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/CertiKAlert\/status\/1763119077524942872\" data-wpel-link=\"external\">stemmed<\/a> from a function in the Seneca protocol\u2019s smart contract code called \u2018performOperations.\u2019 This function, open to external calls, lacked adequate validation for its inputs.<\/p>\n<p>The absence of input validation is a critical oversight in smart contract development. Exploiting this flaw, the attacker crafted specific data to trigger conditions, enabling them to invoke any contract on the blockchain with arbitrary data.<\/p>\n<p>This capability grants the attacker unrestricted access to interact with other contracts, masquerading as vulnerable ones. As a result, the attacker proceeded to transfer assets from addresses authorized to the now-compromised contracts.<\/p>\n<p>Crypto security researcher Daniel Von Fange <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/danielvf\/status\/1762862834252210224\" data-wpel-link=\"external\">discovered<\/a> the flaw and was allegedly expelled from the project\u2019s Discord server, where the team was removing mentions of the exploit.<\/p>\n<p>According to Peck Shield\u2019s latest <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/PeckShieldAlert\/status\/1763109818766946512\" data-wpel-link=\"external\">update<\/a>, the exploiter sent 1,537 Ethereum to a Seneca address, which is the main address connected to the exploit. The hacker retained 300 ETH, worth approximately $1 million, and received the 20% reward offered by Seneca. Subsequently, they transferred the ETH to two separate addresses.<\/p>\n<p>Seneca Protocol suffered a massive breach on February 28th that resulted in its native token SEN extending 80% losses in a day. Initially, losses were estimated to be around 3 million, but further investigation revealed that over 1,900 Ether, worth around $6.4 million, were stolen in the exploit.<\/p>\n<p>Later, Seneca issued a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/SenecaUSD\/status\/1762999045109248461\" data-wpel-link=\"external\">statement<\/a> that it is collaborating with experts to investigate the exploit. The protocol then announced a reward of $1.2 million for the recovery of the stolen funds.<\/p>\n<h2>Seneca\u2019s Confirmation<\/h2>\n<p>Seneca <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/SenecaUSD\/status\/1763181438113865960\" data-wpel-link=\"external\">confirmed<\/a> in an official update on Wednesday that 80% of the funds have been successfully returned. It said that the exploit primarily targeted assets held in users\u2019 wallets, clarifying that Seneca\u2019s own funds were not directly affected.<\/p>\n<p>Instead, the exploit focused on external user assets within the Seneca ecosystem.<\/p>\n<blockquote>\n<p>\u201cThe Chamber code deployed is the exact same as that which underwent the audit, except for fixes explicitly suggested by the auditing company and implemented in the precise ways indicated. An audit is in no way a guarantee of absolute safety, but it\u2019s worth noting that Seneca chose to work with a major auditing company for the very purpose of securing the Chamber contract.\u201d<\/p>\n<\/blockquote>\n<div class=\"code-block code-block-12\" style=\"margin: 8px 0;clear: both\">\n<div><span style=\"font-size:11px;color: gray\">SPECIAL OFFER (Sponsored)<\/span><br \/>\n<b>Binance Free $100 (Exclusive): <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptopotato.com\/pl\/binancebanner\" data-wpel-link=\"internal\">Use this link<\/a> to register and receive $100 free and 10% off fees on Binance Futures first month<\/b> (<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptopotato.com\/buy-bitcoin-5-easy-steps\/\" data-wpel-link=\"internal\">terms<\/a>).<\/div>\n<\/div>\n<p><!-- AI CONTENT END 1 --><\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Seneca Protocol hacker has given back $5.3 million worth of Ether tokens after draining $6.4 million on Ethereum and Arbitrum networks. Initial investigations suggested that an approval mechanism bug in the protocol\u2019s smart contract was exploited. The stablecoin protocol had recently confirmed roping in with law enforcement but offered leniency, stating the team wouldn\u2019t [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":70646,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[230,225,221,227,226,228,229,60,223,224,222],"class_list":["post-257057","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency","tag-brave","tag-coinbase","tag-crypto","tag-decentralised","tag-decentralized","tag-decentralized-exchange","tag-erc-20","tag-featured","tag-meme-coin","tag-robinhood","tag-solana"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/257057","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=257057"}],"version-history":[{"count":2,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/257057\/revisions"}],"predecessor-version":[{"id":257062,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/257057\/revisions\/257062"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/70646"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=257057"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=257057"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=257057"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}