Cryptocurrency [SC] Supply Chain [loss] $3M+

"Inside the Hunt for the Jay Pegs Auto Mart Thief and 865 ETH"

2021-09-17 [vendor] SushiSwap [chain] ethereum
Primary Source ↗
Financial Loss $3.0M (3,000,000 USD)
Blockchain(s) Ethereum

Incident Details

SushiSwap’s token platform, Miso, was hit with a supply chain attack that landed the attacker more than $3 million worth of Ethereum. Malicious code was injected into the platform’s frontend by a contractor who submitted a pull request. The attacker was able to target a car-themed NFT auction called “Jay Pegs Auto Mart”. However, the team discovered the identity of the attacker and the funds were returned after some legal threats.

Total loss estimated at $3,000,000.

Technical Details

Initial Attack Vector
Software supply chain attack
Vendor / Product
SushiSwap
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2021-09-17 Breach occurred
  2. 2021-09-17 Publicly disclosed