Concord has confirmed that its blockchain was hit by a severe safety breach, after an attacker managed to mint 4 billion unauthorized ONE tokens and commenced dumping them throughout exchanges. The Concord ONE exploit triggered a pointy value crash inside hours and has reignited considerations in regards to the community’s safety file, simply years after one of many largest cross-chain bridge hacks in crypto historical past.
Key takeaways
- Concord confirmed an exploit involving the unauthorized minting of 4 billion ONE tokens.
- X consumer Juiceberg first flagged the minting and tracked the attacker’s token actions onchain.
- About 97% of the minted tokens have already reached exchanges and been bought or parked on the market, leaving roughly 115 million ONE nonetheless to dump.
- ONE’s value fell 34% in 24 hours to round $0.0008, placing the stolen tokens’ worth at roughly $3.2 million.
- Concord’s Horizon bridge was beforehand drained of almost $100 million in 2022, an assault the FBI later tied to North Korea’s Lazarus Group and APT 38.
Unauthorized Minting Exploit on Concord Blockchain
The breach got here to mild after an unbiased observer, not Concord itself, noticed uncommon exercise on the community. An X consumer going by Juiceberg reported that an attacker had minted 4 billion ONE tokens with out authorization, exploiting what seemed to be a niche involving empty blocks. Concord later confirmed the exploit instantly, addressing Juiceberg’s publish in its personal assertion on X.
Particulars of the Exploit and Token Impression
In line with Juiceberg’s monitoring, the totalSupply endpoint didn’t instantly mirror the sudden improve in tokens, which made the unauthorized minting more durable to detect in actual time. That delay doubtless gave the attacker a window to start shifting funds earlier than the broader market caught on. Unauthorized minting of this scale instantly inflates the circulating provide of ONE, diluting the worth held by each different holder even earlier than a single token is bought.
Market Response and Token Valuation
The market response was fast. ONE token dropped 34% in 24 hours, buying and selling at round $0.0008, in accordance with figures reported by The Block. At that value, the stolen tokens carry a present worth of roughly $3.2 million — a comparatively modest greenback determine by crypto-hack requirements, however one that also represents a significant hit to a token already buying and selling at fractions of a cent. This value collapse illustrates why unauthorized minting is handled as such a extreme menace: it doesn’t simply steal funds, it actively erodes the token’s market worth for each holder concurrently.
Scope of Token Motion Submit-Exploit
Many of the stolen provide has already left the attacker’s management. Juiceberg’s onchain evaluation discovered that the attacker has roughly 115 million ONE left to promote, which represents about 2.9% of the roughly 4 billion tokens initially minted. In different phrases, the overwhelming majority of the exploit has already performed out.
“The overwhelming majority (~97%) is already on exchanges and has both been bought or is sitting in deposit wallets able to promote,” Juiceberg wrote, describing how rapidly the attacker moved to transform the illicit tokens into liquid funds. That pace suggests the attacker anticipated detection and moved to money out earlier than exchanges or Concord may react.
Ongoing Response and Investigation
Concord says it’s now working with its inner staff and related exchanges in an effort to halt and freeze the stolen funds earlier than extra of the remaining 115 million tokens might be liquidated. The platform additionally confirmed it’s creating a patch for the vulnerability and evaluating rollback choices, although no timeline has been given for both repair.
Standing of Root Trigger Evaluation and Investigation
What stays unclear is precisely how the attacker pulled this off. Concord has not disclosed the technical root explanation for the exploit, and the incident remains to be beneath investigation. The Block reported that it had reached out to Concord for additional particulars, underscoring how a lot about this incident remains to be unconfirmed even because the monetary fallout is already seen in ONE’s value chart.
Context: Concord’s Earlier Main Hack and Safety Challenges
This isn’t Concord’s first brush with a large-scale safety failure. In June 2022, the mission’s Horizon cross-chain bridge was exploited, with attackers making off with crypto belongings valued at almost $100 million, together with Ethereum and varied stablecoins. Safety researchers on the time linked that breach to a compromise of the bridge’s multi-signature pockets.
2022 Horizon Cross-Chain Bridge Exploit Particulars
The Horizon bridge hack stays one of many extra infamous DeFi exploits of its period, each for its measurement and for what investigators finally uncovered about who was behind it.
FBI Attribution of 2022 Hack to North Korean State-Backed Hackers
In January 2023, the FBI formally attributed the 2022 assault to North Korean state-backed hacking teams Lazarus Group and APT 38. That attribution positioned Concord amongst a rising listing of crypto platforms focused by state-sponsored actors, and it raised broader questions on the time in regards to the safety of cross-chain infrastructure throughout the trade.
Concord launched its mainnet in 2019 as a proof-of-stake blockchain, positioning itself as a sooner and cheaper different to Ethereum. ONE serves because the community’s native token, used for transaction charges, staking, and governance — which is exactly why any menace to its provide integrity carries outsized weight for the ecosystem constructed on prime of it.
Whether or not this latest breach seems to be an remoted technical flaw or an indication of deeper structural weaknesses will doubtless form how exchanges, builders, and holders view Concord’s long-term safety posture going ahead. For now, the precedence for Concord’s staff is simple: cease the remaining tokens from hitting the market earlier than the patch is prepared.
FAQ
What occurred within the current Concord ONE token exploit?
An attacker minted 4 billion ONE tokens unauthorizedly, inflicting a major value drop and motion of tokens to exchanges.
How is Concord responding to the exploit?
Concord is working with groups and exchanges to freeze stolen funds, develop a patch, and is investigating the basis trigger.
What influence did the exploit have on the ONE token value?
The ONE token value fell 34% inside 24 hours and was buying and selling round $0.0008 on the time of the report.
Has Concord skilled comparable safety incidents earlier than?
Sure, in June 2022, Concord’s Horizon cross-chain bridge was exploited, leading to almost $100 million stolen, an assault the FBI later attributed to North Korea’s Lazarus Group and APT 38.
Article produced with the help of synthetic intelligence and reviewed by the editorial staff.
