Cryptocurrency [loss] $5M+

"Blockchain, 'Decentralized' Exchange Taken Offline After Hacker Steals Millions"

2022-06-08 [vendor] Osmosis chain attack [chain] cosmos
Primary Source ↗
Financial Loss $5.0M (5,000,000 USD)
Blockchain(s) Cosmos

Incident Details

The Osmosis chain was halted on June 8 after users discovered a bug where people could deposit money into Osmosis pools and receive 3x the amount when they withdrew. The bug was first reported in a public Reddit post where a user posted, “Bug on Osmosis There is a serious problem with osmosis. If you add liquidity to a pool and then remove it, it grows by 50%! How can we fix this!?!? Pools empty by morning!“Developers halted the chain before liquidity pools were fully drained, but estimated that about $5 million was lost. They wrote that they were working on recovery plan; perhaps they will also encourage their community to report bugs privately, rather than via public Reddit post.

Total loss estimated at $5,000,000.

Technical Details

Initial Attack Vector
Software bug / unintentional loss
Vendor / Product
Osmosis chain attack

Timeline

  1. 2022-06-08 Breach occurred
  2. 2022-06-08 Publicly disclosed