Cryptocurrency [loss] $1M+

"Aurory’s USDC pool drained on Arbitrum’s DEX Camelot"

2023-12-17 [vendor] Aurory bridge [chain] solana, ethereum
Primary Source ↗
Financial Loss $1.2M (1,188,000 USD)
Blockchain(s) Solana, Ethereum

Incident Details

The Aurory gaming platform uses a bridge called SyncSpace to move assets between the blockchain and the game’s off-chain network. On December 17, the bridge was targeted on Arbitrum’s Camelot DEX, and an attacker successfully siphoned around 600,000 $AURY tokens from the liquidity pool. As a result, the pool went from around $1.5 million in liquidity to around $312,000, and the price of the $AURY token dropped 11% as the attacker sold it off in bulk.The Aurory team posted on Twitter to acknowledge the hack, writing that they’d disabled SyncSpace as they investigated. They also wrote that SyncSpace had been audited months ago, but that the audit had failed to detect the vulnerability.

Total loss estimated at $1,188,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
Aurory bridge

Timeline

  1. 2023-12-17 Breach occurred
  2. 2023-12-17 Publicly disclosed