"Alex Bridge Incident Anlaysis"
Primary Source ↗Incident Details
An attacker tried to pull off what could have been a $12 million heist from ALEX Lab’s XLink bridge after a private key was compromised. However, the sloppy work by the attacker enabled an apparent whitehat hacker to step in.The attacker was successfully able to transfer around 13.8 million STX ($2 million) on the Stack BTC layer-2 chain. However, their attempts to steal assets notionally worth around $4.3 million from the project’s BNB Chain implementation failed when they upgraded the project contract to a malicious version, but failed to prevent other people from calling the withdraw function. The attacker’s first transactions to withdraw the funds themself failed, and an apparent whitehat hacker was able to step in and complete the withdrawal ahead of the exploiter. They later negotiated a deal for the funds’ return, after offering a 10% “bounty”.The exploiter had also tried, and failed, to steal assets notionally worth around $5 million on the Ethereum blockchain, but failed to do so. ALEX Lab later announced they were able to recover or secure around $4.5 million of those assets. ALEX also later announced that they believed the attackers were part of the North Korean Lazarus Group.
Total loss estimated at $6,300,000.
Technical Details
- Initial Attack Vector
- Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise
- Vendor / Product
- ALEX XLink bridge theft
Timeline
- 2024-05-14 Breach occurred
- 2024-05-14 Publicly disclosed