DeFi project known as Wormhole hit with a potential $430 million hack

Online thieves made away with 120,000 wETH, or so-called wrapped Ether, said Wormhole. PHOTO: REUTERS

NEW YORK (BLOOMBERG) - Wormhole, a communication bridge between Solana and other decentralised-finance blockchain networks, said hackers stole about US$320 million (S$431.3 million) in cryptocurrency.

The online thieves made away with 120,000 wETH, or so-called wrapped Ether, the project's team said on Twitter. They pledged to add Ether over the next several hours to ensure the wETH is backed one-for-one and get the network back up. The post did not elaborate on where they would get the Ether. The vulnerability has been patched, they said in a follow-up post.

"This demonstrates once again that the security of DeFi services has not reached a level that is appropriate for the huge sums being stored within them," said Dr Tom Robinson, co-founder of blockchain analysis firm Elliptic. "The transparency of the blockchain is allowing attackers to identify and exploit major bugs."

The hack is likely one of the largest thefts from a DeFi protocol, which bill themselves as allowing users to bypass traditional intermediaries to borrow and lend digital assets.

About 96,000 of the wETH tokens have been sent to the Ethereum blockchain, according to another forensics provider, TRM Labs. "No onward movement yet, but we are tracking the situation," TRM said.

Wormhole developers offered the hacker a US$10 million bug bounty for exploit details and the return of the funds.

Jump Trading Group announced in August that it bought Certus One, which helped develop Wormhole. Jump has said it is a founding code contributor to Wormhole. Certus One offers infrastructure services for proof-of-stake blockchains and has been an active participant in decentralised networks including Cosmos, Terra, Solana and next-generation Ethereum.

A representative for Jump Trading did not immediately respond to a request for comment.

The Wormhole hack adds to a slew of problems for Solana, the blockchain that brags lower transaction fees than main rival Ethereum. Last fall, Solana was down for 17 hours after attacks by trading software bots. Bots also degraded the network's performance recently.

Solana's SOL token is down 9 per cent in the last 24 hours, according to tracker CoinMarketCap.com.

Join ST's Telegram channel and get the latest breaking news delivered to you.