Nomad to crypto thieves: Please give us back 90%, keep 10% as a reward. Deal?
(2022/08/05)
- Reference: 1659728639
- News link: https://www.theregister.co.uk/2022/08/05/nomad_white_hat_payback/
- Source link:
Cryptocurrency bridge Nomad sent a message to the looters who drained nearly $200 million in tokens from its coffers earlier this week: return at least 90 percent of the ill-gotten gains, keep 10 percent as a bounty for discovering the security flaw, and Nomad will consider this a "white-hat" hack, as opposed to plain old theft, and not take legal action.
The crypto firm proposed this [1]deal via tweet, along with the wallet address on Ethereum to which funds should be return. It also warned: "Nomad is continuing to work with its community, law enforcement and blockchain analysis first to ensure all funds are returned."
Update: Nomad Bridge Hack Bounty(see below for details)Please send the funds to the official Nomad recovery wallet address on Ethereum: 0x94A84433101A10aEda762968f6995c574D1bF154 [2]https://t.co/8gO1xVl5IC [3]pic.twitter.com/8D7SvbDQlO — Nomad (⤭⛓🏛) (@nomadxyz_) [4]August 4, 2022
Nomad previously [5]noted it was working with blockchain analysis outfit TRM Labs and custodian bank Anchorage Digital to trace the flow of stolen funds and coordinate the safe return of the tokens.
A subsequent blog post highlights the fact that even though Nomad is willing to let the thieves off easy for the heist, it [6]can't guarantee that law enforcement will turn a blind eye.
In a FAQ section of the blog, Nomad answers the question: Am I safe from civil liability or criminal prosecution if I retain 10 percent of the funds I took? The crypto firm reiterates that it will not pursue any legal action against what it sees as white hats. And then it added:
Nomad will also identify you as a white hat to any third parties who may be considering legal action.
Nomad is working closely with law enforcement and will advocate for no criminal charges when white hats return funds.
In other words, as ethical hackers have found out the hard way in earlier research efforts, the US Justice Department may still [7]press charges . At the time of publication the DoJ didn't respond to The Register 's inquiry about the likelihood of this happening.
The company confirmed the [8]heist on Tuesday. After the initial attack, folks with [9]several dozen addresses joined in the looting by copying transactions and inserting their wallets to receive funds.
[10]How a crypto bridge bug led to a $200m 'decentralized crowd looting'
[11]Solana, Phantom blame Slope after millions in crypto-coins stolen from 8,000 wallets
[12]Capital One: Convicted techie got in via 'misconfigured' AWS buckets
[13]US won't prosecute 'good faith' security researchers under CFAA
While at least [14]$17 million has been recovered, the cyber-ransacking highlighted the security risks around these bridges with recent security snafus totaling more than $1 billion in swiped funds: Ronin Bridge ( [15]$600 million ); Qubit Bridge ( [16]$80 million ); Wormhole Bridge ( [17]$320 million ); Meter.io Bridge ( [18]$4.4 million ); and Poly Network Bridge ( [19]$610 million that was returned ).
Nomad's blog post also explained the reasoning behind waiting a few days to announce the so-called bounty.
[20]
"Given the unprecedented number of decentralized parties involved, coordinating amongst everyone was a complex process," it said. "We wanted to make sure we put the bounty out in the right way, so we took some additional time to make sure we considered the complexities due to the nature of the hack." ®
Get our [21]Tech Resources
[1] https://twitter.com/nomadxyz_/status/1555293965049630722
[2] https://t.co/8gO1xVl5IC
[3] https://t.co/8D7SvbDQlO
[4] https://twitter.com/nomadxyz_/status/1555293965049630722?ref_src=twsrc%5Etfw
[5] https://twitter.com/nomadxyz_/status/1554679735006859264
[6] https://medium.com/nomad-xyz-blog/nomad-bridge-hack-bounty-and-faqs-d7726aaf359e
[7] https://www.theregister.com/2022/05/20/cfaa_rule_change/
[8] https://www.theregister.com/2022/08/02/flash_mob_robs_nomad_crypto/
[9] https://twitter.com/PeckShieldAlert/status/1554350737957998592
[10] https://www.theregister.com/2022/08/02/flash_mob_robs_nomad_crypto/
[11] https://www.theregister.com/2022/08/04/solana_wallet_slope/
[12] https://www.theregister.com/2022/06/20/captial_one_wire_fraud/
[13] https://www.theregister.com/2022/05/20/cfaa_rule_change/
[14] https://twitter.com/nomadxyz_/status/1555045760588140544
[15] https://cointelegraph.com/news/the-aftermath-of-axie-infinity-s-650m-ronin-bridge-hack
[16] https://news.bitcoin.com/hacker-siphons-80-million-from-qubit-cross-chain-bridge-largest-defi-exploit-of-2022-to-date/
[17] https://www.theregister.com/2022/02/04/wormhole_currency_theft/
[18] https://cointelegraph.com/news/latest-defi-bridge-exploit-results-in-4-4m-losses-for-meter
[19] https://www.cnbc.com/2021/08/23/poly-network-hacker-returns-remaining-cryptocurrency.html
[20] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yu2TAxDWbHgW5Czd9wDOTAAAABU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[21] https://whitepapers.theregister.com/
The crypto firm proposed this [1]deal via tweet, along with the wallet address on Ethereum to which funds should be return. It also warned: "Nomad is continuing to work with its community, law enforcement and blockchain analysis first to ensure all funds are returned."
Update: Nomad Bridge Hack Bounty(see below for details)Please send the funds to the official Nomad recovery wallet address on Ethereum: 0x94A84433101A10aEda762968f6995c574D1bF154 [2]https://t.co/8gO1xVl5IC [3]pic.twitter.com/8D7SvbDQlO — Nomad (⤭⛓🏛) (@nomadxyz_) [4]August 4, 2022
Nomad previously [5]noted it was working with blockchain analysis outfit TRM Labs and custodian bank Anchorage Digital to trace the flow of stolen funds and coordinate the safe return of the tokens.
A subsequent blog post highlights the fact that even though Nomad is willing to let the thieves off easy for the heist, it [6]can't guarantee that law enforcement will turn a blind eye.
In a FAQ section of the blog, Nomad answers the question: Am I safe from civil liability or criminal prosecution if I retain 10 percent of the funds I took? The crypto firm reiterates that it will not pursue any legal action against what it sees as white hats. And then it added:
Nomad will also identify you as a white hat to any third parties who may be considering legal action.
Nomad is working closely with law enforcement and will advocate for no criminal charges when white hats return funds.
In other words, as ethical hackers have found out the hard way in earlier research efforts, the US Justice Department may still [7]press charges . At the time of publication the DoJ didn't respond to The Register 's inquiry about the likelihood of this happening.
The company confirmed the [8]heist on Tuesday. After the initial attack, folks with [9]several dozen addresses joined in the looting by copying transactions and inserting their wallets to receive funds.
[10]How a crypto bridge bug led to a $200m 'decentralized crowd looting'
[11]Solana, Phantom blame Slope after millions in crypto-coins stolen from 8,000 wallets
[12]Capital One: Convicted techie got in via 'misconfigured' AWS buckets
[13]US won't prosecute 'good faith' security researchers under CFAA
While at least [14]$17 million has been recovered, the cyber-ransacking highlighted the security risks around these bridges with recent security snafus totaling more than $1 billion in swiped funds: Ronin Bridge ( [15]$600 million ); Qubit Bridge ( [16]$80 million ); Wormhole Bridge ( [17]$320 million ); Meter.io Bridge ( [18]$4.4 million ); and Poly Network Bridge ( [19]$610 million that was returned ).
Nomad's blog post also explained the reasoning behind waiting a few days to announce the so-called bounty.
[20]
"Given the unprecedented number of decentralized parties involved, coordinating amongst everyone was a complex process," it said. "We wanted to make sure we put the bounty out in the right way, so we took some additional time to make sure we considered the complexities due to the nature of the hack." ®
Get our [21]Tech Resources
[1] https://twitter.com/nomadxyz_/status/1555293965049630722
[2] https://t.co/8gO1xVl5IC
[3] https://t.co/8D7SvbDQlO
[4] https://twitter.com/nomadxyz_/status/1555293965049630722?ref_src=twsrc%5Etfw
[5] https://twitter.com/nomadxyz_/status/1554679735006859264
[6] https://medium.com/nomad-xyz-blog/nomad-bridge-hack-bounty-and-faqs-d7726aaf359e
[7] https://www.theregister.com/2022/05/20/cfaa_rule_change/
[8] https://www.theregister.com/2022/08/02/flash_mob_robs_nomad_crypto/
[9] https://twitter.com/PeckShieldAlert/status/1554350737957998592
[10] https://www.theregister.com/2022/08/02/flash_mob_robs_nomad_crypto/
[11] https://www.theregister.com/2022/08/04/solana_wallet_slope/
[12] https://www.theregister.com/2022/06/20/captial_one_wire_fraud/
[13] https://www.theregister.com/2022/05/20/cfaa_rule_change/
[14] https://twitter.com/nomadxyz_/status/1555045760588140544
[15] https://cointelegraph.com/news/the-aftermath-of-axie-infinity-s-650m-ronin-bridge-hack
[16] https://news.bitcoin.com/hacker-siphons-80-million-from-qubit-cross-chain-bridge-largest-defi-exploit-of-2022-to-date/
[17] https://www.theregister.com/2022/02/04/wormhole_currency_theft/
[18] https://cointelegraph.com/news/latest-defi-bridge-exploit-results-in-4-4m-losses-for-meter
[19] https://www.cnbc.com/2021/08/23/poly-network-hacker-returns-remaining-cryptocurrency.html
[20] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yu2TAxDWbHgW5Czd9wDOTAAAABU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[21] https://whitepapers.theregister.com/
Re: Please send the funds to the official Nomad recovery wallet address on Ethereum: 0x94A...
Doctor Syntax
Oh, I don't know. It looks pretty much like cryptocurrency industry standard operating practice to me.
Re: Please send the funds to the official Nomad recovery wallet address on Ethereum: 0x94A...
JassMan
And how do we know that once the funds are returned to the "Nomad" wallet, that they will be distributed back to the original owners, not the CFO's account who then disappears to tax haven.
Re: Please send the funds to the official Nomad recovery wallet address on Ethereum: 0x94A...
HildyJ
Shirley no crypto CFO would do that?
"we took some additional time to make sure we considered the complexities"
Pascal Monett
Too bad you didn't take additional time to consider complexities when you set up your useless infrastructure.
Return the money ?
So, not only are you incompetent, but you also believe in Santa Claus ?
Go ahead and file a complaint. I wish you luck.
Please send the funds to the official Nomad recovery wallet address on Ethereum: 0x94A...
Seriously, they're asking people to send millions of dollars to address x in a fucking tweet?
@nomadxyz_ sure looks like an official company account to me..........