In one of the most severe events this year, the web3 game Munchables on the Blast layer-2 platform experienced a cyberattack, resulting in a significant loss of funds for the gaming platform. As reported by blockchain researcher ZachXBT, the attack resulted in the loss of 17,400 ETH, equal to $62.5 million. What caught my attention was that the developer who stole the funds returned them without any conditions.
Hacker Revealed as North Korean Group Member.
The source of the attack is being speculated, with ZachXBT saying that it is related to North Korea, the country previously implicated in targeting different crypto projects such as the Ronin Network, CoinEx, Stake, Atomic Wallet, and Harmony.
Further research by ZachXBT demonstrated that the malicious actor was an employee of the Munchables and had the opportunity to modify some parts of the smart contract code and provide unauthorized access.
Besides, ZachXBT unearthed proof of collusion between four Munchables developers and the exploiter. Such persons, presumably the same person, recommended each other for a job, regularly moved money in the accounts jointly used for exchange and donated money to each other.
Hacker Dev Returns Stolen Funds, Ending Well.
Despite the odds, the members of Blast Core have accumulated $97 million in a multi-signature wallet after a lot of work in the background. In the same way, the Munchables ex-developer who took funds voluntarily returned them without any ransom demands, demonstrating a good ending.
To assist in the recovery of user funds, the Munchables developer published all the relevant private keys. This includes key 3, holding $62,535,441.24, another key of 73 WETH, and an owner key for the rest. Surprisingly, he has agreed to give away these keys without any conditions; thus, a quick settlement of this crisis was ensured.
Conclusion
Though the severity of the attack can’t be underestimated, Munchables will continue to maintain users’ security by not enforcing lockdrops. Furthermore, all Blast-related rewards will be made available as planned, and more updates will be foreseen in the coming days.
While the investigation proceeds and the rescue operations persist, all key players are still on standby, looking forward to the next developments after this critical cyberattack on the Web3 gaming platform.
Earn more PRC tokens by sharing this post. Copy and paste the URL below and share to friends, when they click and visit Parrot Coin website you earn: https://parrotcoin.net0
PRC Comment Policy
Your comments MUST BE constructive with vivid and clear suggestion relating to the post.
Your comments MUST NOT be less than 5 words.
Do NOT in any way copy/duplicate or transmit another members comment and paste to earn. Members who indulge themselves copying and duplicating comments, their earnings would be wiped out totally as a warning and Account deactivated if the user continue the act.
Parrot Coin does not pay for exclamatory comments Such as hahaha, nice one, wow, congrats, lmao, lol, etc are strictly forbidden and disallowed. Kindly adhere to this rule.
Constructive REPLY to comments is allowed