🚨 Swamps Security Incident Detailed Report 🚨
Yesterday, a significant security breach was executed by a former developer, leading to unauthorized access and transactions within our network. We are committed to full transparency in our community and will detail each step of the exploit:
Initial Proxy Manipulation (May-22-2024 03:36:13 AM 2 UTC): The exploiter initiated the attack by creating a new Locker contract to gain ownership rights over it.
Specific Action: As the owner of the proxy, the exploiter created a new contract, giving us ownership of the contract but not the proxy itself. We believed we had full control as it was also confirmed by another developer, who, in reality, was colluding with the exploiter in this scheme.
Evidence of Breach:
swamps-explorer.tc.l2aas.com…
Contract Swap Fraud (May-22-2024 03:45:43 AM 2 UTC): Stealthily switched the implementation of the proxy to the malicious contract, crafted to siphon funds.
Contract Change Details:
swamps-explorer.tc.l2aas.com…
Introduction of Malicious Withdrawal Function (May-22-2024 03:47:53 AM 2 UTC): The exploiter Installed a function, called "Xxx" in the new contract to unilaterally transfer all contained funds on the proxy.
Function Execution: The function was called to withdraw the entirety of the locked funds to a wallet controlled by the exploiter.
Unauthorized Withdrawal:
swamps-explorer.tc.l2aas.com…
Massive Token Transfers:
First Major Transfer (May-22-2024 03:51:29 AM 2 UTC): Diverted 173,871,089 GSWP to an external wallet, initiating the large-scale theft.
swamps-explorer.tc.l2aas.com…
Second Major Transfer (May-22-2024 03:57:35 AM 2 UTC): Further transferred 100,000,000 GSWP, consolidating the stolen assets.
swamps-explorer.tc.l2aas.com…
Liquidating NakaChain and Uniswap Pools:
The exploiter bridged funds to NakaChain and Uniswap and then sold all tokens into pools.
On NakaChain (May-22-2024 04:16:18 AM 2 UTC):
Tx 1:
- Amount: 173,870,890.75789896
$GSWP
- Details:
explorer.nakachain.xyz/tx/0x…
Tx 2 (May-22-2024 04:17:20 AM 2 UTC):
- Amount: 99,999,791.37263154
$GSWP
- Details:
explorer.nakachain.xyz/tx/0x…
Then he bridged those funds to the Bitcoin network (May-22-2024 04:18:14 AM 2 UTC):
explorer.nakachain.xyz/tx/0x…
- Receiving transaction on Bitcoin Network:
mempool.space/fr/tx/4166a3ea…
On Uniswap:
Tx 1 (May-22-2024 04:26:35 AM 2 UTC):
- Amount: 29,999,998
$GSWP
- Details:
etherscan.io/tx/0xa1099b537c…
His address (same used to exploit our pools and Locker contract):
etherscan.io/token/0x15ecf5e…
Exploitation of Liquidity Pools (May-22-2024 04:06:57 AM 2 UTC): Used non-disclosed, non-verified contracts to drain liquidity pools initialized on Swamps DEX.
Mechanism Used: Deployed a hidden smart contract to manipulate pool transactions, allowing unauthorized siphoning of funds.
Liquidity Exploitation example:
swamps-explorer.tc.l2aas.com…
Asset Bridging and Liquidation: Systematically moved the stolen assets across networks to his EVM address: 0x7273a4cAEd4E3CccE1354B47De03772f20dDd243.
Bridge and Liquidation Strategy: Used cross-network bridges to transfer and subsequently liquidate the assets for Ethereum and Bitcoin, reducing traceability.
First Bridge Transaction (May-22-2024 04:08:17 AM 2 UTC):
swamps-explorer.tc.l2aas.com…
We are actively working with cybersecurity experts and law enforcement to address this issue and recover the funds. New security measures are being implemented to strengthen our system and prevent such incidents in the future.
We appreciate your support and understanding as we navigate this challenge. Continuous updates will be provided to keep our community informed every step of the way. Your trust is our top priority, and we are dedicated to restoring and maintaining it.