• bitcoinBitcoin (BTC) $ 117,468.00
  • ethereumEthereum (ETH) $ 3,911.33
  • xrpXRP (XRP) $ 3.32
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 787.90
  • solanaSolana (SOL) $ 175.32
  • usd-coinUSDC (USDC) $ 0.999784
  • staked-etherLido Staked Ether (STETH) $ 3,902.88
  • dogecoinDogecoin (DOGE) $ 0.222267
  • tronTRON (TRX) $ 0.338452
  • cardanoCardano (ADA) $ 0.786877
  • wrapped-stethWrapped stETH (WSTETH) $ 4,730.59
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 117,455.00
  • stellarStellar (XLM) $ 0.438626
  • hyperliquidHyperliquid (HYPE) $ 40.94
  • suiSui (SUI) $ 3.78
  • chainlinkChainlink (LINK) $ 18.47
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,194.21
  • bitcoin-cashBitcoin Cash (BCH) $ 582.25
  • hedera-hashgraphHedera (HBAR) $ 0.259778
  • wrapped-eethWrapped eETH (WEETH) $ 4,195.49
  • avalanche-2Avalanche (AVAX) $ 23.34
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • litecoinLitecoin (LTC) $ 122.70
  • wethWETH (WETH) $ 3,913.02
  • leo-tokenLEO Token (LEO) $ 8.97
  • the-open-networkToncoin (TON) $ 3.34
  • usdsUSDS (USDS) $ 0.999323
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999877
  • whitebitWhiteBIT Coin (WBT) $ 44.23
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 117,508.00
  • uniswapUniswap (UNI) $ 10.42
  • polkadotPolkadot (DOT) $ 3.86
  • bitget-tokenBitget Token (BGB) $ 4.50
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.19
  • moneroMonero (XMR) $ 266.78
  • crypto-com-chainCronos (CRO) $ 0.149790
  • pepePepe (PEPE) $ 0.000011
  • aaveAave (AAVE) $ 284.99
  • ethenaEthena (ENA) $ 0.636396
  • daiDai (DAI) $ 0.999914
  • bittensorBittensor (TAO) $ 370.34
  • mantleMantle (MNT) $ 1.05
  • ethereum-classicEthereum Classic (ETC) $ 21.52
  • nearNEAR Protocol (NEAR) $ 2.65
  • ondo-financeOndo (ONDO) $ 1.01
  • aptosAptos (APT) $ 4.42
  • internet-computerInternet Computer (ICP) $ 5.35
  • pi-networkPi Network (PI) $ 0.361783
  • okbOKB (OKB) $ 45.98
  • jito-staked-solJito Staked SOL (JITOSOL) $ 214.28
  • kaspaKaspa (KAS) $ 0.090697
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,906.22
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.037131
  • algorandAlgorand (ALGO) $ 0.264023
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • usd1-wlfiUSD1 (USD1) $ 0.999626
  • arbitrumArbitrum (ARB) $ 0.416712
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.236562
  • vechainVeChain (VET) $ 0.024415
  • cosmosCosmos Hub (ATOM) $ 4.47
  • bonkBonk (BONK) $ 0.000026
  • gatechain-tokenGate (GT) $ 16.79
  • fasttokenFasttoken (FTN) $ 4.58
  • render-tokenRender (RENDER) $ 3.80
  • worldcoin-wldWorldcoin (WLD) $ 1.02
  • official-trumpOfficial Trump (TRUMP) $ 9.23
  • story-2Story (IP) $ 6.24
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,456.69
  • susdssUSDS (SUSDS) $ 1.06
  • binance-staked-solBinance Staked SOL (BNSOL) $ 186.46
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.688045
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.06
  • sei-networkSei (SEI) $ 0.308236
  • skySky (SKY) $ 0.083166
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,105.26
  • flare-networksFlare (FLR) $ 0.023952
  • filecoinFilecoin (FIL) $ 2.49
  • spx6900SPX6900 (SPX) $ 1.82
  • quant-networkQuant (QNT) $ 114.18
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 117,104.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.498400
  • xdce-crowd-saleXDC Network (XDC) $ 0.091859
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,113.17
  • usdtbUSDtb (USDTB) $ 1.00
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,205.64
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,176.59
  • injective-protocolInjective (INJ) $ 14.04
  • usdt0USDT0 (USDT0) $ 0.999060
  • hash-2Provenance Blockchain (HASH) $ 0.027867
  • nexoNEXO (NEXO) $ 1.34
  • kucoin-sharesKuCoin (KCS) $ 10.51
  • blockstackStacks (STX) $ 0.738050
  • curve-dao-tokenCurve DAO (CRV) $ 0.948067
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,114.64
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998669
  • celestiaCelestia (TIA) $ 1.73
  • pump-funPump.fun (PUMP) $ 0.003567
  • falcon-financeFalcon USD (USDF) $ 1.00
  • optimismOptimism (OP) $ 0.715837
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 1.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 117,657.00
  • conflux-tokenConflux (CFX) $ 0.224246
  • flokiFLOKI (FLOKI) $ 0.000117
  • wbnbWrapped BNB (WBNB) $ 787.89
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 198.04
  • fartcoinFartcoin (FARTCOIN) $ 1.04
  • immutable-xImmutable (IMX) $ 0.541525
  • paypal-usdPayPal USD (PYUSD) $ 0.999623
  • saros-financeSaros (SAROS) $ 0.382445
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999318
  • the-graphThe Graph (GRT) $ 0.095563
  • sonic-3Sonic (S) $ 0.303801
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 40.95
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 117,480.00
  • pax-goldPAX Gold (PAXG) $ 3,393.67
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.78
  • dogwifcoindogwifhat (WIF) $ 0.953365
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.12
  • lido-daoLido DAO (LDO) $ 1.06
  • ethereum-name-serviceEthereum Name Service (ENS) $ 27.74
  • clbtcclBTC (CLBTC) $ 118,517.00
  • kaiaKaia (KAIA) $ 0.149400
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.33
  • super-oethSuper OETH (SUPEROETH) $ 3,912.71
  • tezosTezos (XTZ) $ 0.807827
  • vaultaVaulta (A) $ 0.530090
  • pendlePendle (PENDLE) $ 5.02
  • tether-goldTether Gold (XAUT) $ 3,382.41
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,187.40
  • msolMarinade Staked SOL (MSOL) $ 230.53
  • theta-tokenTheta Network (THETA) $ 0.813466
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 4,065.88
  • iotaIOTA (IOTA) $ 0.199279
  • aerodrome-financeAerodrome Finance (AERO) $ 0.873574
  • memecoreMemeCore (M) $ 0.458878
  • raydiumRaydium (RAY) $ 2.84
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,909.45
  • jasmycoinJasmyCoin (JASMY) $ 0.015696
  • galaGALA (GALA) $ 0.016422
  • pyth-networkPyth Network (PYTH) $ 0.122893
  • ousgOUSG (OUSG) $ 112.09
  • the-sandboxThe Sandbox (SAND) $ 0.284989
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,914.55
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998781
  • tbtctBTC (TBTC) $ 117,300.00
  • bittorrentBitTorrent (BTT) $ 0.00000067
  • jito-governance-tokenJito (JTO) $ 1.79
  • morphoMorpho (MORPHO) $ 1.98
  • ripple-usdRipple USD (RLUSD) $ 0.999929
  • zcashZcash (ZEC) $ 38.16
  • stader-ethxStader ETHx (ETHX) $ 4,163.94
  • syrupMaple Finance (SYRUP) $ 0.499832
  • flowFlow (FLOW) $ 0.372147
  • rekt-4Rekt (REKT) $ 0.000001
  • newton-projectAB (AB) $ 0.008132
  • usual-usdUsual USD (USD0) $ 0.997723
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 117,535.00
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,912.98
  • walrus-2Walrus (WAL) $ 0.404456
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.222203
  • decentralandDecentraland (MANA) $ 0.296030
  • based-brettBrett (BRETT) $ 0.056586
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 116,604.00
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,315.77
  • build-onBUILDon (B) $ 0.552046
  • heliumHelium (HNT) $ 2.88
  • vision-3Vision (VSN) $ 0.176242
  • usddUSDD (USDD) $ 1.00
  • bitcoin-svBitcoin SV (BSV) $ 26.46
  • coredaoorgCore (CORE) $ 0.523434
  • beldexBeldex (BDX) $ 0.073553
  • swethSwell Ethereum (SWETH) $ 4,286.39
  • telcoinTelcoin (TEL) $ 0.005605
  • mog-coinMog Coin (MOG) $ 0.000001
  • true-usdTrueUSD (TUSD) $ 0.998972
  • chain-2Onyxcoin (XCN) $ 0.014126
  • starknetStarknet (STRK) $ 0.126308
  • dexeDeXe (DEXE) $ 8.49
  • reserve-rights-tokenReserve Rights (RSR) $ 0.008161
  • keetaKeeta (KTA) $ 1.18
  • apecoinApeCoin (APE) $ 0.597470
  • thorchainTHORChain (RUNE) $ 1.36
  • apenftAPENFT (NFT) $ 0.00000047
  • arweaveArweave (AR) $ 7.13
  • dydx-chaindYdX (DYDX) $ 0.612287
  • ether-fiEther.fi (ETHFI) $ 1.10
  • frax-etherFrax Ether (FRXETH) $ 3,887.57
  • compound-governance-tokenCompound (COMP) $ 48.41
  • zebec-networkZebec Network (ZBCN) $ 0.005277
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,911.81
  • savings-daiSavings Dai (SDAI) $ 1.16
  • superfarmSuperVerse (SUPER) $ 0.725717
  • neoNEO (NEO) $ 6.30
  • instadappFluid (FLUID) $ 6.66
  • elrond-erd-2MultiversX (EGLD) $ 15.27
  • tripTrip (TRIP) $ 14.70
  • sun-tokenSun Token (SUN) $ 0.022561

‘Sherlock missed it’: Cork hacker slams audit firms in on-chain messages

0 11

‘Sherlock missed it’: Cork hacker slams audit firms in on-chain messages

The hacker behind last month’s $12 million exploit of Cork Protocol has weighed in on a debate between squabbling crypto security audit firms.

Messages left on-chain from the hacker’s address appear to set the record straight about the root causes of the incident and lament the clout-chasing of some auditors in the wake of such attacks.

The comments came in response to a post made on Wednesday by Jack Sanford, CEO of security audit firm Sherlock. Sandford accuses competitors Spearbit and Cantina of missing the vulnerability and covering up their failures.

In the first message, the hacker states “sherlock missed it.” Minutes later, they moved 4,530 ether — currently valued at $11.6 million — to a new address.

The debate

On May 28, a16z-backed Cork Protocol announced a “security incident affecting the wstETH:weETH market” and a temporary pause of all markets. The post-mortem report that followed stated that “the attacker exploited an access control vulnerability in the Cork Hook, which none of our audits flagged.”

However, Sanford’s post points to the commit hashes submitted in various auditors’ reports, as evidence that the supposed vulnerability did not fall within their scope.

He then highlights Cantina’s failure to provide such hashes and how Spearbit is yet to release their report publicly, despite it being overdue.

In the initial message left by the hacker, they seemingly correct the assumed root cause of the exploit, stating “uniswap hook is not problem,” pouring cold water on the idea that the bug was only present in later versions of the code.

The dressing-down

The attacker then followed up with “a really big bombshell,” written in Estonian, in which they appear to contradict themselves by stating that “Sherlock didn’t miss it,” and that “there are many ways to take DS, not just the Uniswap hook.”

He warns that all companies that missed the initial bug “should not be trusted.”

Somewhat ironically, the hacker’s main beef appears to be with blockchain security companies that capitalize on the attention brought by hacks.

Firms that “failed to detect the real problem” in their assessments allegedly include Dedaub, Three Sigma, Halborn, Blocksec, and many others.

The hacker says firms that look for promotion by releasing analysis before the official post-mortem “are not recommended.”

In a final message, sent hours later, the hacker doubles down on its attack on audit firms that “write nonsense about bugs to promote their brands and profit from the efforts of others.”

They call out Dedaub’s Neville Grech in particular, accusing him of “promoting your brands by analyzing bugs that you can’t detect yourself.”

The Cork Protocol culprit?

The content of these later messages suggests the hacker may well be a member of the security researcher community with an axe to grind. Others certainly seem to think so.

If so, it wouldn’t be the first time suspicions were raised about an established figure in the scene being a blackhat. Earlier this year, Nick L. Franklin, a prolific researcher who claimed to have “analyzed every major blockchain hack,” was linked to the $50 million Radiant Capital hack.

Source

Leave A Reply

Your email address will not be published.

Verified by MonsterInsights