CertiK Alert analysts reported the hacking of the Alex Labs DeFi platform on the bitcoin network. The losses amounted to about $4.3 million.
#CertiKInsight 🚨
We have seen a suspicious transaction affecting @ALEXLabBTC
Initial evidence points to a possible private key compromise.
Deployer of 0xb3955302E58FFFdf2da247E999Cd9755f652b13b upgrades to a suspicious implementation.
In total ~$4.3m worth of assets have… pic.twitter.com/02kiw2dFrm
Experts suspect a possible leak of private keys.
According to on-chain data, the incident occurred after the contract updates of the Bridge Endpoint platform in the BNB Chain. After that, an unknown person withdrew 16 BTC, 3.3 million USDC and 2.7 million Sugar Kingdom Odyssey (SKO) from the protocol bridge.
Calling the update operation actually changed the implementation address to an untested bytecode, making this change unnoticeable at first glance.
The hacker's address created two unverified contracts on May 10 and two more on May 14. Prior to this, there was no wallet activity.
After the updates began, the proxy address of the bridge contract triggered an untested function of another account, as a result of which the funds went to the criminal's wallet.
According to analysts, it is possible that the attacker tried to attack the protocol on other networks, since Alex Labs contract updates were also initiated in Ethereum.
Representatives of the DeFi project confirmed the hacking of the XLink bridge. The team announced cooperation with many exchanges and the successful freezing of some of the stolen funds.
ALEX Security Update
We want to update our community about a recent exploit involving the XLink bridge. We are actively collaborating with exchanges, partners, and ecosystem contributors to address the situation. A significant amount of the funds associated with the hacker has…
Alex Labs also added that they had already identified the identity of the hacker and offered him to return the assets for a 10% reward by May 18.
Recall that on May 14, an attacker began to "siphon" funds from traders of the decentralized Equalizer exchange, stealing tokens worth tens of thousands of dollars.
Earlier, on-chain researcher ZachXBT reported a possible hacking of the Bahrain-based Rain cryptocurrency exchange for $14.8 million.