2023.02.01 - BonqDAO and AllianceBlock
Category: Other
Updated: 8 Feb 2023
On February 1, 2023, the Hypernative platform detected in real-time an exploit on Polygon targeting the protocols BonqDAO and AllianceBlock. The attack was an oracle manipulation in which the price of the AllianceBlock tokens was manipulated. The attacker gained access to 110M ALBT tokens and managed to redeem 500K USDC of BEUR (belongs to BonqDAO). The 500K USDC were transfered to the attacker’s Ethereum address along with 113.8M WALBT. The ALBT tokens were then sold multiple times for ETH. The attacker used Tornado Cash for cashing out. The BonqDAO protocol lost around $120M, while the attacker gained around $1.7M.
We have refrained from publicly disclosing this as we first approached the involved protocols (as we always do). Both protocols involved have requested us to not publicly disclose the suspected hack so they can contain and damage with less pressure. Following our alert to the protocols, they have halted trading and worked on remediation. We have also presented them with our initial findings.
Comments