Data leak [loss] $3M+

"Shido token plummets 94% as exploiter drains Ethereum staking contract"

2024-02-28 [vendor] Shido contract
Primary Source ↗
Financial Loss $3.3M (3,300,000 USD)

Incident Details

The Shido blockchain suffered an exploit of their staking smart contract, in which an attacker was able to transfer ownership of the contract to another address and then upgrade the contract with a function that allowed them to withdraw staked tokens. Altogether, the attacker withdrew all 4.3 billion staked $SHIDO tokens — over half the entire circulating supply.Although the stolen tokens were nominally priced at $35 million, the massive theft caused the price to plummet 94%. The attacker has converted the stolen tokens to around 956 ETH ($3.3 million).The Shido team announced that they would be trying to offer a “bounty” to the hacker.

Total loss estimated at $3,300,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
Shido contract

Timeline

  1. 2024-02-28 Breach occurred
  2. 2024-02-28 Publicly disclosed