Cryptocurrency
[SC] Supply Chain
[loss] $3M+
"Inside the Hunt for the Jay Pegs Auto Mart Thief and 865 ETH"
Primary Source ↗Financial Loss
$3.0M
(3,000,000 USD)
Blockchain(s)
Ethereum
Incident Details
SushiSwap’s token platform, Miso, was hit with a supply chain attack that landed the attacker more than $3 million worth of Ethereum. Malicious code was injected into the platform’s frontend by a contractor who submitted a pull request. The attacker was able to target a car-themed NFT auction called “Jay Pegs Auto Mart”. However, the team discovered the identity of the attacker and the funds were returned after some legal threats.
Total loss estimated at $3,000,000.
Technical Details
- Initial Attack Vector
- Software supply chain attack
- Vendor / Product
- SushiSwap
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2021-09-17 Breach occurred
- 2021-09-17 Publicly disclosed