Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Zak Wolff. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Zak Wolff or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

E2 - Inverse Hydra 4/9/2022

37:14
 
Share
 

Manage episode 325060017 series 3337136
Content provided by Zak Wolff. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Zak Wolff or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

https://hackmd.io/@idegen/E2-Inverse-Hydra

1) Ronin Bridge Attack update

2) Seven Lapsus$ group hackers arrested

Why this?
Infamous crypto hackers, sim swappers, and all around general obnoxious blackhats.

When: 4/2

What happened: Former hacking partners turned on this main guy and doxxed him. Law enforcement circled in.

Who:

  • group that tried to blackmail Nvida into open-sourcing GPUs (likely so they could be modified and used for crypto mining)
  • Mostly teens so names aren’t released but
Under his online moniker “White” or “Breachbase” the teenager, who is autistic, is said to be behind the prolific Lapsus$ hacker crew, which is believed to be based in South America.

3) Buble Gum Ape Heist - Bored ape holder “s27” traded their bubble gum ape and matching mutant derivatives with floor value of $567k for a basic ass photoshopped imposter apes

Why cover this?
As if we needed another reminder that NFT markets are sketchy and the absolute simplicity of the scam.

Raises important questions around NFT verification.

What: simple photoshop scam

The victim entered into a direct swap trade with the scammer via a third-party service called swap.kiwi. Unlike regular marketplaces like OpenSea, platforms like swapkiwi allow direct NFT swaps between collectors, reducing transaction (“gas”) fees.

Unknown to s27, the other participant in the trade put up knock-off NFTs in exchange for s27’s legitimate Bored Ape and Mutant Apes. The scammer used images of actual Bored Apes to create fake replicas and uploaded the same ones to OpenSea.
-https://www.theblockcrypto.com/post/140702/bored-ape-holder-loses-nfts-worth-567000-to-a-scammer

where: kiwi.swap
Who: anon & s27
When: 4/1-3/2022

It’s unclear if the scammer actually used Photoshop or some other editor.

4) Hydra Darknet Market bust

when: 4/5/2022
what is Hydra:

the world’s largest darknet market by revenue.Hydra specialized in same-day ‘dead drop’ services, where drug dealers (vendors) hide packages in public places before informing customers of the pick-up locationThe market primarily caters to criminals in Russia and surrounding nations. “Treasuremen,” or dealers connected with the site, push drugs throughout the region by hiding them in geo-tagged pickup locations.The website launched in 2015 selling drugs, hacked materials, forged documents and illegal digital services such as Bitcoin-mixing - which cyber-criminals use to launder stolen or extorted digital coins.The site was written in Russian, with sellers located in Russia, Ukraine, Belarus, Kazakhstan and surrounding countries.Police say 17 million customers and more than 19,000 seller accounts were registered on the marketplace, which now carries a police seizure notice.after a tip-off, German police seized the Hydras servers and confiscated €23m (£16.7m) in Bitcoin. 25.2 million USDHydra was seemingly impervious to police attempts to stop it.

-BBC

Germany’s federal police shut down the Russia-based Hydra Market, the world’s largest darknet market by revenue. Later in the day, the Justice Department followed up by indicting one of Hydra’s key operators, and the U.S. Treasury’s Office of Foreign Assets Control (OFAC) sanctioned Hydra, adding more than 100 of its cryptocurrency addresses to the SDN list as identifiers.In 2021, Hydra received more than $1.7 billion worth of cryptocurrency, which accounts for over 75% of all darknet market revenue globally.

- Chain Analysis

Who?:
Dmitry Olegovich Pavlov is said to be the mastermind behind Hydra.

5) Inverse Finance Hack

15M taken in exceptionally clever defi attack.

What is Inverse Finance?

Inverse Finance is a community of cryptocurrency enthusiasts organized as a Decentralized Autonomous Organization (DAO), started on the 26th of December 2020. Inverse DAO governs and develops a suite of permissionless and decentralized finance tools using blockchain smart contract technology. The code base is open-source, and maintained by the community.

Inverse Marketing Pitch

Master the Game Of Positive Sum DeFiHere at Inverse Finance, we’re decentralized by design, moving past reckless, outdated systems towards a better solution: Positive Sum Defi. We help you maximize your earnings via revenue sharing, accumulate high yields with sustainable APYs, and benefit from low-cost stable coin borrowing. Join our community to grow and thrive.

Why this?

  • Oracle Manipulation is not new in defi, but does represent one of the most fascinating classes of exploits in crypto right now. I want to call these defi anti-pattern attacks but that’s probably not the most technically accurate description.
  • 15.6 Million is not a huge amount in the world of crypto hacks, but the complexity and style of the attack is worth note.

When: 4/2/2022
Who: anon

What happened:
From Inverse Twitter:

This morning Inverse Finance’s money market, Anchor, was subject to a capital-intensive manipulation of the INV/ETH price oracle on Sushiswap, resulting in a sharp rise in the price of INV which subsequently enabled the attacker to borrow $15.6 million in DOLA, ETH, WBTC, & YFI

From Rekt.news

A professionally executed hack allowed an anonymous actor to manipulate the price of INV and help themself to an exclusive deal from the ETH based lending protocol.
  continue reading

22 episodes

Artwork
iconShare
 
Manage episode 325060017 series 3337136
Content provided by Zak Wolff. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Zak Wolff or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

https://hackmd.io/@idegen/E2-Inverse-Hydra

1) Ronin Bridge Attack update

2) Seven Lapsus$ group hackers arrested

Why this?
Infamous crypto hackers, sim swappers, and all around general obnoxious blackhats.

When: 4/2

What happened: Former hacking partners turned on this main guy and doxxed him. Law enforcement circled in.

Who:

  • group that tried to blackmail Nvida into open-sourcing GPUs (likely so they could be modified and used for crypto mining)
  • Mostly teens so names aren’t released but
Under his online moniker “White” or “Breachbase” the teenager, who is autistic, is said to be behind the prolific Lapsus$ hacker crew, which is believed to be based in South America.

3) Buble Gum Ape Heist - Bored ape holder “s27” traded their bubble gum ape and matching mutant derivatives with floor value of $567k for a basic ass photoshopped imposter apes

Why cover this?
As if we needed another reminder that NFT markets are sketchy and the absolute simplicity of the scam.

Raises important questions around NFT verification.

What: simple photoshop scam

The victim entered into a direct swap trade with the scammer via a third-party service called swap.kiwi. Unlike regular marketplaces like OpenSea, platforms like swapkiwi allow direct NFT swaps between collectors, reducing transaction (“gas”) fees.

Unknown to s27, the other participant in the trade put up knock-off NFTs in exchange for s27’s legitimate Bored Ape and Mutant Apes. The scammer used images of actual Bored Apes to create fake replicas and uploaded the same ones to OpenSea.
-https://www.theblockcrypto.com/post/140702/bored-ape-holder-loses-nfts-worth-567000-to-a-scammer

where: kiwi.swap
Who: anon & s27
When: 4/1-3/2022

It’s unclear if the scammer actually used Photoshop or some other editor.

4) Hydra Darknet Market bust

when: 4/5/2022
what is Hydra:

the world’s largest darknet market by revenue.Hydra specialized in same-day ‘dead drop’ services, where drug dealers (vendors) hide packages in public places before informing customers of the pick-up locationThe market primarily caters to criminals in Russia and surrounding nations. “Treasuremen,” or dealers connected with the site, push drugs throughout the region by hiding them in geo-tagged pickup locations.The website launched in 2015 selling drugs, hacked materials, forged documents and illegal digital services such as Bitcoin-mixing - which cyber-criminals use to launder stolen or extorted digital coins.The site was written in Russian, with sellers located in Russia, Ukraine, Belarus, Kazakhstan and surrounding countries.Police say 17 million customers and more than 19,000 seller accounts were registered on the marketplace, which now carries a police seizure notice.after a tip-off, German police seized the Hydras servers and confiscated €23m (£16.7m) in Bitcoin. 25.2 million USDHydra was seemingly impervious to police attempts to stop it.

-BBC

Germany’s federal police shut down the Russia-based Hydra Market, the world’s largest darknet market by revenue. Later in the day, the Justice Department followed up by indicting one of Hydra’s key operators, and the U.S. Treasury’s Office of Foreign Assets Control (OFAC) sanctioned Hydra, adding more than 100 of its cryptocurrency addresses to the SDN list as identifiers.In 2021, Hydra received more than $1.7 billion worth of cryptocurrency, which accounts for over 75% of all darknet market revenue globally.

- Chain Analysis

Who?:
Dmitry Olegovich Pavlov is said to be the mastermind behind Hydra.

5) Inverse Finance Hack

15M taken in exceptionally clever defi attack.

What is Inverse Finance?

Inverse Finance is a community of cryptocurrency enthusiasts organized as a Decentralized Autonomous Organization (DAO), started on the 26th of December 2020. Inverse DAO governs and develops a suite of permissionless and decentralized finance tools using blockchain smart contract technology. The code base is open-source, and maintained by the community.

Inverse Marketing Pitch

Master the Game Of Positive Sum DeFiHere at Inverse Finance, we’re decentralized by design, moving past reckless, outdated systems towards a better solution: Positive Sum Defi. We help you maximize your earnings via revenue sharing, accumulate high yields with sustainable APYs, and benefit from low-cost stable coin borrowing. Join our community to grow and thrive.

Why this?

  • Oracle Manipulation is not new in defi, but does represent one of the most fascinating classes of exploits in crypto right now. I want to call these defi anti-pattern attacks but that’s probably not the most technically accurate description.
  • 15.6 Million is not a huge amount in the world of crypto hacks, but the complexity and style of the attack is worth note.

When: 4/2/2022
Who: anon

What happened:
From Inverse Twitter:

This morning Inverse Finance’s money market, Anchor, was subject to a capital-intensive manipulation of the INV/ETH price oracle on Sushiswap, resulting in a sharp rise in the price of INV which subsequently enabled the attacker to borrow $15.6 million in DOLA, ETH, WBTC, & YFI

From Rekt.news

A professionally executed hack allowed an anonymous actor to manipulate the price of INV and help themself to an exclusive deal from the ETH based lending protocol.
  continue reading

22 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play