{"id":203127,"date":"2021-03-16T05:37:24","date_gmt":"2021-03-16T02:37:24","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/hacker-makes-off-with-5-7m-after-ransacking-social-token-platform\/"},"modified":"2021-03-16T05:37:24","modified_gmt":"2021-03-16T02:37:24","slug":"hacker-makes-off-with-5-7m-after-ransacking-social-token-platform","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/hacker-makes-off-with-5-7m-after-ransacking-social-token-platform\/","title":{"rendered":"# Hacker makes off with $5.7m after ransacking social token platform"},"content":{"rendered":"<p>&#8220;<strong># Hacker makes off with $5.7m after ransacking <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">social<\/a> token platform <\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMDMvNmM1YThhY2YtZmQ4NC00OTMyLWEzNmMtZTgzN2ZmNmIxMzFmLmpwZw==.jpg\" \/><\/p>\n<div class=\"post-content\" data-v-5a136f3a>Social token platform Roll suffered a hot wallet breach, resulting in hackers draining at least 3,000 ETH worth $5.7 million on March 15.\u00a0<\/p>\n<p>At roughly 8am UTC, digital asset management platform MyCrypto <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/MyCrypto\/status\/1371012290229628930?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1371012290229628930%7Ctwgr%5E%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fcryptoslate.com%2Fhackers-steal-3000-eth-from-roll-causing-massive-price-dumps-of-nearly-100%2F\">reported<\/a> that a hacker may have compromised the private keys for Roll\u2019s hot wallet, allowing them to transfer funds from users\u2019 accounts at will. <\/p>\n<p>After <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>roximately 12 hours, Roll <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/tryroll.com\/security-incident\/\">responded<\/a> to the attack, announcing the hacker had stolen and liquidated a large number of tokens, and that withdrawals had been suspended across the platform: <\/p>\n<blockquote><p>\u201cThe attacker has sold all the tokens. There is no further user action suggested.\u201d <\/p><\/blockquote>\n<p>Roll added that it had launched a $500,000 fund to \u201chelp creators and their communities&#8221; affected by the incident.<\/p>\n<p>The attacker stole 11 different social tokens, including $WHALE, $RARE, and $PICA. The stolen funds were then transferred to Tornado Cash, a privacy tool often used by hackers to launder stolen funds. The hacker then traded the tokens for Ether on the popular decentralized exchange, Uniswap.<\/p>\n<p>Markets for the tokens stolen in the breach began to dump within hours of the attack, quickly accumulating losses of more than 90%. Some of the worst-hit included $PICA, $WHALE, and $FWB, who plummetted 99.6%, 99.3%, and 92.35% respectively. <\/p>\n<p>As a result of the attack, the market cap of social tokens on the platform fell from $1.5 billion as of March 12 to $365 million as of this writing.<\/p>\n<p>With only 2.17% of its supply <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/WhaleShark_Pro\/status\/1371032207838437376?s=20\">compromised<\/a>, $WHALE was one of the only tokens to quickly recover, trading above $30 at the time of writing. <\/p>\n<p>A social token is an ERC-20 token users can create on platforms like Roll in order to engage with their community or sell assets.<\/p>\n<p>Roll\u2019s reaction to the breach has garnered mixed reactions on Twitter, with the $500k fund receiving particular attention. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">500 000$ fund??<br \/>I&#8217;m a creator and our community just lost EVERYTHING..<\/p>\n<p>The <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/search?q=%24PICA&amp;src=ctag&amp;ref_src=twsrc%5Etfw\">$PICA<\/a> just went to 0&#8230; <br \/>I lost like months of salary<\/p>\n<p>As smaller creative communities we just expect more than this.. Hoping for a full refund. Confidence there will be seriously damaged either way<\/p>\n<p>\u2014 Maxime Hacquard (@HacquardMaxime) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/HacquardMaxime\/status\/1371246050611200003?ref_src=twsrc%5Etfw\">March 14, 2021<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Twitter user \u201cLoB\u201d <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/LINKorBust\/status\/1371184734571687937?s=20\">added<\/a>: \u201c$10 million in a hot wallet without the multisig that you promised creators was in place, 12 hours to make a response to the incident, and $500k to be split across a dozen projects? Yikes.\u201d<\/p>\n<p><template data-name=\"subscription_form\" data-type=\"markets_outlook\"><\/template><\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/hacker-makes-off-with-5-7m-after-ransacking-social-token-platform\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;# Hacker makes off with $5.7m after ransacking social token platform &#8221; Social token platform Roll suffered a hot wallet breach, resulting in hackers draining at least 3,000 ETH worth $5.7 million on March 15.\u00a0 At roughly 8am UTC, digital asset management platform MyCrypto reported that a hacker may have compromised the private keys for&#8230;<\/p>\n","protected":false},"author":1,"featured_media":203128,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/images\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMDMvNmM1YThhY2YtZmQ4NC00OTMyLWEzNmMtZTgzN2ZmNmIxMzFmLmpwZw==.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[74894,74891,74882,80098,70944],"class_list":["post-203127","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-blockchain","tag-ethereum","tag-hacks","tag-private-keys","tag-hackers"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/203127","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=203127"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/203127\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/203128"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=203127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=203127"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=203127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}