By Jon Rice & Dan Smith
Translator: Odaily Planet Daily Translator | Nian Yin Sitang
In a collaborative effort between Jump Crypto and Oasis, the hackers who attacked Wormhole in February 2022 appear to have become the “victims.”
Just over a year ago (February 3, 2022), the Wormhole cross-chain bridge was hacked, becoming one of the largest security incidents in the crypto industry. A total of approximately 120,000 ETH were stolen, worth up to $325 million at the time.
Afterwards, Jump Crypto announced that it would invest 120,000 Ethereum to compensate for the theft of Wormhole and support the continued development of Wormhole. Jump Crypto said that it believes in the prospect of multi-chain and believes that Wormhole is an essential infrastructure in the future, so it will continue to support Wormhole and help it continue to develop.
Jump Crypto, based in Chicago, is the cryptocurrency division of Jump Trading and is involved in the development of the Wormhole protocol.
At the time, Wormhole offered hackers a $10 million bug bounty and white hat agreement in exchange for returning the funds. But that never seemed to happen.
“We’re consulting very closely with government resources and private resources, many of whom are experts in tracking down these types of criminals,” Dave Olsen, president and chief investment officer of Jump Trading Group, told Bloomberg a month later. “We’re going to be fighting this all the time. So this is not something that we’re going to be distracted from next month or next year. This is a permanent effort.”
According to on-chain analysis from Blockworks Research, Jump ultimately won the battle. Just three days ago, the funds appeared to have been recovered.
Jump Crypto declined to comment on the findings, and Oasis did not respond to a request for comment.
However, Oasis released a statement following the publication of this article, stating:
“On February 21, 2023, we received an order from the High Court of England and Wales requiring us to take all necessary steps to recover certain assets held in wallet addresses associated with the February 2, 2022 Wormhole attack. As required by law, this was done under court order using Oasis Multisig and court-authorized third parties.
We can also confirm that, as required by the court order, the assets were immediately transferred to a wallet controlled by an authorized third party. We do not retain control or access to these assets.”
Blockworks Research analyst Dan Smith described the process in detail:
“Transaction history indicates that Jump Crypto and Oasis worked together to reverse engineer an upgradeable Oasis contract to access stolen funds from the vault of the initial Wormhole attacker.
The attacker has been moving stolen funds through various Ethereum applications. They recently opened two Oasis vaults, establishing leveraged long positions on two ETH collateralized derivatives. Importantly, both vaults use the automated services provided by Oasis.
Several wallets were involved in this counter exploit. Each address is defined and named for use throughout the analysis:
- Oasis Multisig: 4 of the 12 Multisigs with Oasis proxy contracts.
- Holder: Currently holding the recovered funds, which appear to belong to Jump.
- Sender: Responsible for executing reverse attacks, seems to belong to Jump.
The process began on February 21st, when Sender was added as a signer to Oasis Multisig. Sender executed 5 transactions to facilitate the reversal attack and was subsequently removed as a signer to Oasis Multisig.
The bulk of the funds recovery process is performed in the third transaction from Sender to Oasis Multisig. To quickly summarize this transaction, Sender “exploits” the Oasis contract, allowing it to transfer collateral and debt from the attacker’s vault to Sender’s own vault.
After taking control of the attacker's vault, a wallet labeled Jump Crypto by several analytics firms sent 80 million DAI to Sender. The DAI was used to repay the vault's outstanding loans and withdraw $218 million in collateral. The recovered collateral was then sent to Holder, where the funds are currently located.
It is unclear whether the Sender and Holder belong to Oasis or Jump. However, the base case assumption is that Jump has control of these addresses because Jump repaid the debt to withdraw the collateral. Neither Jump nor Oasis have confirmed this.
Thus, Jump appears to have successfully fought back against the Wormhole attacker and recovered the ETH that was stolen from it a year ago. Excluding the repayment of DAI to recover the collateral, the net proceeds of the reverse attack were approximately $140 million.”
Cross-chain bridge attacks have been responsible for many of the largest thefts in the crypto industry, including the $540 million Ronin hack, which was later attributed to the North Korean hacking group Lazarus.
However, transparent, open, permissionless public blockchains are proving to be a “secret weapon” in the fight against financial crime.
The ethics, and even legality, of hacking will likely be debated in the future, but for now, Jump Crypto appears to have made $140 million more than it did last week.
Meanwhile, one hacker may be secretly regretting missing out on a $10 million bug bounty and a get-out-of-jail-free card.
