Cryptocurrency trading platform BitMart has disclosed a
“large-scale security breach” that it blamed on a stolen private
key, resulting in the theft of more than $150 million in various
cryptocurrencies.
The breach is said to have impacted two of its hot wallets on
the Ethereum (ETH) blockchain and the Binance smart chain (BSC).
The company noted[1]
that the wallets carried only a “small percentage” of the assets.”
Hot wallets, as opposed to their cold counterparts, are connected
to the internet and allow cryptocurrency owners to receive and send
tokens.
Blockchain security and data analytics company PeckShield
estimated[2]
the total loss to be around $200 million, calling the whole chain
of events as “Pretty straightforward: transfer-out, swap, and
wash.”
“This security breach was mainly caused by a stolen private key
that had two of our hot wallets compromised,” BitMart’s chief
executive Sheldon Xia said[3]
in a series of tweets sent out earlier today. In light of the
incident, BitMart said it’s temporarily suspending withdrawals
until further notice and added a thorough security review was
underway, with plans to resume the operations on December 7.
The development is the latest in a wave of hacks that have
targeted cryptocurrency platforms such as PolyNetwork, Cream Finance[4], Liquid[5], and bZx[6], among others.
Last week, malicious actors orchestrated a heist amounting to
$120 million worth of Bitcoin and Ether assets from BadgerDAO[7], a decentralized finance
(DeFi) lending service. In a separate development, blockchain
startup MonoX Finance disclosed[8]
that a hacker stole $31 million by exploiting a bug in software the
service uses to draft smart contracts.
And in August, an unnamed attacker stole more than $600 million[9] worth of tokens from the
cryptocurrency platform PolyNetwork, only to return[10] nearly all of the money
two weeks later.
References
Read more https://thehackernews.com/2021/12/hackers-steal-200-million-worth-of.html