Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesBotsEarnCopy
Loopring suffers $5 million hack after 'Guardian' two-factor authentication service is compromised

Loopring suffers $5 million hack after 'Guardian' two-factor authentication service is compromised

The BlockThe Block2024/06/09 15:31
By:The Block

Quick Take Loopring, the ZK-rollup based protocol built on Ethereum, had its two-factor authentication based Guardian wallet recovery service compromised in a hack, the company recently disclosed. About $5 million was drained from wallets protected by Loopring’s Guardian service, blockchain data shows.

Loopring LRC -4.76% , the zkEVM protocol built on Ethereum with a website that bills its smart wallet application as "Ethereum's most secure wallet," suffered a security breach related to its 'Guardian' two-factor authentication service, the protocol announced on Sunday. 

Through the Guardian service, users can elect to name wallets of trusted individuals or institutions to assist in security operations such as locking a compromised wallet or restoring one if the seed phrase is lost. However, a hacker managed to bypass Loopring's own Official Guardian service to instigate recoveries on wallets with that single guardian without the users' permission, Loopring disclosed in its announcement. As more than half of guardians are needed to instigate transactions, according to Loopring's website , wallets that used multiple guardians or a different, third-party guardian were protected from the exploit. 

Loopring also shared two wallet addresses the protocol says were involved in the security breach. Blockchain data shows one wallet was able to drain about $5 million worth of tokens from the affected wallets. 

"We are actively collaborating with Mist security experts to determine how our 2FA service was compromised. To protect our users, we have temporarily suspended Guardian-related and 2FA-related operations. Following this action, the compromise has ceased," the protocol wrote in its announcement on X. Loopring was unable to be immediately reached for comment by The Block. 

Loopring also reported that it's working with law enforcement to trace the perpetrator and requested that anyone with additional information about the hack share it with the protocol. 

While the attack was likely a surprise for the team, Loopring's risk disclosure statement identifies a compromise to its Guardian service as a potential attack vector, and recommends users identify at least three guardians. "After your Wallet is created, we will add Loopring Official Guardian service to your Wallet by default. As a centralized service, Loopring Official Guardian may be attacked and controlled by hackers," Loopring's website reads . 

Loopring's native token has fallen about 5% in the last 24 hours following the protocol's disclosure of the hack, according to The Block's Price Page . 


0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Bullish, Gibraltar Partner on Crypto Derivatives Settlement Framework

Bullish, the cryptocurrency exchange backed by Peter Thiel, has partnered with the Government of Gibraltar and the Gibraltar Financial Services Commission to co-develop a regulatory framework for the clearing and settling crypto derivatives.

DeFi Planet2025/05/14 10:00
Bullish, Gibraltar Partner on Crypto Derivatives Settlement Framework

Arizona Governor Vetoes Pro-Crypto Bills, Signs Strict Bitcoin ATM Regulation

Arizona Governor Katie Hobbs has made a decisive move on the state’s approach to digital assets, vetoing multiple cryptocurrency-friendly bills while signing a strict regulatory measure for Bitcoin ATM operations into law.

DeFi Planet2025/05/14 10:00
Arizona Governor Vetoes Pro-Crypto Bills, Signs Strict Bitcoin ATM Regulation

Australia’s Crypto Sector Welcomes Pro-Crypto Appointment in Government Reshuffle

Australia’s digital asset industry is showing renewed optimism following the appointment of Andrew Charlton as Assistant Minister for the Digital Economy, Artificial Intelligence, and other emerging technologies. The announcement was made by Prime Minister Anthony Albanese during a press conference in Canberra on May 12, marking a significant shift in the government’s approach to emerging tech sectors.

DeFi Planet2025/05/14 10:00
Australia’s Crypto Sector Welcomes Pro-Crypto Appointment in Government Reshuffle