Hacker transfers $70M out of payment platform UPCX
Update April 1, 1:42 pm UTC: This article has been updated to add comments from Cyvers co-founder and chief technology officer Meir Dolev.An unauthorized party withdrew about $70 million in digital assets from open-sourc...
Update April 1, 1:42 pm UTC: This article has been updated to add comments from Cyvers co-founder and chief technology officer Meir Dolev.
An unauthorized party withdrew about $70 million in digital assets from open-source payment platform UPCX, according to a security alert issued on April 1.
The blockchain security firm Cyvers flagged suspicious activity involving 18.4 million UPC tokens, estimating the value of the compromised funds at $70 million.
Cyvers said someone accessed a UPCX address and upgraded its ProxyAdmin contract. The attacker then executed a function that allows admins to withdraw, leading to fund transfers from three different management accounts.
At the time of writing, the stolen tokens had not been swapped for other crypto assets.
Cointelegraph contacted UPCX for comment but did not receive an immediate response.
UPC price dips 7% following unauthorized transferUPCX acknowledged it had detected “unauthorized activity” involving its management accounts. The team suspended deposits and withdrawals for UPCX in response to the incident. It said user assets are unaffected by the issue and it is actively investigating the matter.
UPC’s token price dropped amid news of the incident. According to CoinGecko, UPC’s token prices dropped 7%, from a high of $4.06 to a low of $3.77 during the incident.
UPCX 24-hour price chart. Source: CoinGecko
Related: Hacker steals $8.4M from RWA restaking protocol Zoth
UPC hack mirrors previous attack patternsIn a statement, Cyvers co-founder and chief technology officer Meir Dolev told Cointelegraph that while the root cause of the attack remained under investigation, these types of incidents often stem from compromised credentials or flawed access control mechanisms.
Dolev told Cointelegraph that both of these vulnerabilities have been the predominant cause of Web3 losses in 2024. The executive said the same causes were responsible for over 80% of the stolen funds during the year.
The cybersecurity executive also said the attack pattern was similar to previous exploits. Dolev told Cointelegraph:
“This incident mirrors attack patterns we’ve documented in prior exploits, where access to critical administrative roles enabled malicious upgrades and fund drainage.”The executive added that the hack underscored an urgent need to enhance security around wallet permissions, multisignature implementations and runtime transaction validation.
The $70 million stolen in the incident would more than double the amount lost in the previous month. In March, crypto stolen from hacks only reached $33 million.
Magazine: Memecoins are ded — But Solana ‘100x better’ despite revenue plunge
Original source
Read on CointelegraphRelated market context
Sky Governance Proposal Seeks To Double USDC PSM Buffer To $800 Million
TL;DR BA Labs has proposed doubling key LITE-PSM-USDC-A parameters in the Sky stablecoin system from 400 million to 800 million. T...
Coinbase Quantum Report Warns Millions Of Bitcoin Could Face Future Security Risks
TL;DR Coinbase’s Quantum Advisory Council published a report on post-quantum migration and abandoned coins. The report estimates t...
Bitcoin price challenges $64,000 weekend wall – needing a breakout or risk a deeper correction
Bitcoin reclaimed $64,000 on June 12 and touched an intraday high of $64,301 in the same session that spot ETF flows finally flipp...
Carlos Domingo: The DTCC is repeating telecom’s mistakes, banks need the Clarity Act more than crypto, and stablecoins set the benchmark for tokenized assets | The Wolf Of All Streets
Financial institutions must choose between proprietary systems or embracing open blockchain technologies for future growth. The po...
Blackrock’s IBIT Leads $86 Million Bitcoin ETF Inflow as Ethereum Funds Extend Outflow Streak
Spot bitcoin exchange-traded funds (ETFs) drew $85.85 million in net inflows on Friday, with every one of the 12 tracked funds avo...
Spot bitcoin ETFs snap five-day outflow streak with $85.8 million Friday inflow as ether funds keep sliding
BlackRock's IBIT led Friday's inflows at $57.7 million, with Fidelity's FBTC adding $18.0 million, while no fund reported a net ou...