Blast Chain's $97 Million Battle: Are North Korean Hackers Rusty?
ID: afe8fdf1-5737-5405-b566-59088d7348fe
STIX ID: report--afe8fdf1-5737-5405-b566-59088d7348fe
Feed Name: CertiK Blog
This report analyzes two March 2024 DeFi attacks: a SSS Token logic bug that allowed arbitrary balance inflation and a larger Munchables proxy/implementation compromise that enabled an attacker (attributed to North Korean actors) to invoke an `unlock` function and drain ~17,413.96 ETH plus other assets; the attacker abused implementation upgrades and delegatecall-based storage manipulation to plant a backdoor, attempted cross-chain transfers, and ultimately returned funds after community intervention.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
