Cryptocurrency [loss] $194,500

Tweet thread by Rabby Wallet

2022-10-11 [vendor] Rabby Wallet [chain] ethereum
Primary Source ↗
Financial Loss $194,500 (194,500 USD)
Blockchain(s) Ethereum

Incident Details

Rabby Swap, a feature of the Rabby crypto wallet, was exploited a month after it was first rolled out. An attacker discovered an apparent vulnerability in the Rabby Swap smart contract that enabled them to arbitrarily transfer other users’ funds. Rabby urged its users to revoke approvals for the contracts across multiple chains.The attack impacted assets on multiple chains. The attacker tumbled 114 ETH ($146,000) through Tornado Cash shortly after the hack, along with 179 BNB ($48,500). The full extent of the attack is still being measured. The buggy contract that enabled the attack had been audited by blockchain security firm PeckShield, but the vulnerability had apparently gone undetected.

Total loss estimated at $194,500.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
Rabby Wallet

Timeline

  1. 2022-10-11 Breach occurred
  2. 2022-10-11 Publicly disclosed