Cointime

Download App
iOS & Android

January 2023 Monthly Skynet Alerts Report

Validated Project

Introduction

So far, in 2023, approximately $28,047,532 was lost to various scams and exploits in the Web3 industry with a total of 55 recorded attacks. This is a significant decrease from the average loss per month in 2022, which stood at $313 million, and is approximately 43% below December's figure, which saw the least amount of funds lost. Exit scams account for approximately $10,222,994 in losses across 21 incidents and made up 38% of the overall funds lost in January. This is due to the lack of any major incidents exceeding over $10 million, which hasn’t occurred for over 12 months.

Major Exploits

In the month of January there have been a total of 27 major attacks. This is the second fewest number of attacks recorded since February 2022, which saw 20 major attacks. An average of $998,734 was lost per attack, which is a significant decrease from the average of $2,455,613 per attack in the month of December.

The largest exploit this month was the LendHub incident, which saw a ~$5.3 million loss. The LendHub exploit, which happened 12th January, is the largest attack this year thus far. The exploiter took advantage of a discrepancy between an old IBSV cToken and a new token. The old and new IBSV tokens exist simultaneously in the market, with both taking their price from the new IBSV. The exploiter obtained old IBSV tokens by depositing HBSV tokens, borrowing assets from the new market, then redeemed HBSV back in the old market. The exploiter transferred the stolen funds from LendHub to other chains like Ethereum and Optimism. After transferring the assets to Ethereum, the exploiter funneled stolen funds into sanctioned cryptocurrency mixer Tornado Cash.

The second largest exploit was on the 3rd January of a GMX whale wallet being compromised, leading to a loss of ~$3.5 million. The GMX was swapped for Ethereum and bridged to the Ethereum mainnet from Abritrum. The victim wallet sets the hackers wallet as the pending receiver, which was then swapped. The swapping of GMX caused a slippage of the GMX token, causing the community to ask questions as to its nature. This prompted figures in GMX to announce that a whale wallet had been hacked, and had nothing to do with the GMX project.

The third moss significant loss, reported on December 31, 2022. One of the original core developers behind Bitcoin Luke Dahjr, claims he lost all his bitcoin as a result of a hack before the new year. Luke claims that the alleged hackers somehow gained access to his private key to steal his BTC. Luke did not share how much of his BTC was stolen in total. The 4 transactions that he posted online at the time of writing suggest that ~$3.6 million was taken. There is no definite answer to how Luke lost his bitcoin, but people speculate that he had lax security, or that someone stumbled across the seed phrase somehow. Some even suggested that it was a boating accident ahead of tax season.

Exit Scams

January 2023 has seen a total of 21 exit scams resulting in the loss of $10.2 million. The amount lost this month to exit scams is approximately the average seen across 2022 when discounting outlier events (exit scams with losses over 10 million). However, exit scams accounted for a significant portion of the overall monthly loss in January, at 38.1%. This compares to 27.2% in December and 5% in November and October, respectively.

The high proportion of the overall funds being attributed to exit scams is likely due to the overall low number of incidents in other categories such as major exploits. While other categories have trended lower, exit scams continued a steady trend seen in 2022. This even comes after a relative drop in incidents in January 2023 compared to the average in 2022. The overall incidents in January 2023 were 21 compared to the overall average of 26.1 in 2022.

Despite the lower incidents, the continuation of the trend of funds lost was maintained primarily by three major exit scams whose funds lost exceeded $2 million. FUT, malicious circulate contracts and Yield Robot resulted in a combined loss of approximately $7 million, roughly 70% of all funds lost in January.

Flash Loans

January 2023 saw a total of 16 attacks. The total number of losses for January were approximately $762,000 with an average of $47,647 lost per attack. The most significant flashloan attack occurred on BRA. On January 9th, 2023, BRA experienced several flashloan attacks that exploited the flawed fee collecting system to cause over minting on the victim liquidity pool which had been drained. Leading to a loss of approximately $237,000. The first attacker address gained 819 BNB and the second attacker address gained 53BNB as the liquidity pool was still vulnerable to copycat attackers. The attacker took advantage of the vulnerability in the fee - collecting system to cause overminting on the victim liquidity pool.

Overall, the number of malicious flash loans was higher than any month seen in 2022; however the overall funds lost didn’t exceed $800,000. It is significantly lower than the 2022 average, which stands at $29.5 million lost per month. Despite the higher number of flash loans, the majority of incidents targeted low liquidity tokens, with the vast majority leading to losses below $50,000.

Discord Hacks and Phishing

The start of 2023 has begun how 2022 ended; there were 36 compromised Discord servers in December 2022 and 36 in January 2023. We also recorded 5 Twitter account compromises related to NFTs in both months. On top of this we are also starting to see an increase in the number of fake Twitter accounts and wallet drainers being advertised on Twitter. This increase may be due to the prevalence of wallet drainer phishing kits, which scammers can purchase from a variety of vendors.

In the largest phishing incident of the month, a fake Cool Cats NFT website was able to steal 357 NFTs. Five days later,the same group were able to steal 195 NFTs from another phishing site imitating Hasbullah NFT. The Hasbullah phishing account is perhaps the first incident in which we have seen being promoted via Twitter ads.

Conclusion

Compared to January 2022, there was an uptick in attacks. In January 2022, we recorded 31 total attacks, while this year we have recorded 54 total attacks. However, when comparing to total loss there was a significant decrease in funds lost. The downward trend in funds lost, which was observed at the end of 2022, has continued into 2023, primarily due to the absence of major exploits where the total loss exceeds $10 million.

Read more: https://www.certik.com/resources/blog/oyUkWBFDI0lMmUuMMGSJA-january-2022-monthly-report

Comments

All Comments

Recommended for you

  • Fed Chair Nominee Waller: Independence Depends on the Fed Itself

    Fed Chair nominee Waller: I will be independent of Trump's opinions. Trump tends to call for the FOMC to cut interest rates. Independence depends on the Fed itself.

  • Digital Bank Revolut's IPO Valuation Could Reach $200 Billion

    The Financial Times reported, citing anonymous investor sources, that the UK digital bank Revolut plans to seek a valuation of $150 billion to $200 billion in its upcoming IPO, a significant increase from its previous valuation of $75 billion. The company's CEO, Nik Storonsky, also revealed that Revolut is preparing for a new round of secondary share sales in the second half of 2026, with a valuation potentially exceeding $100 billion.

  • ETH Falls Below $2300

    Market data shows that ETH has fallen below $2300, currently priced at $2299.92, with a 24-hour decline of 0.38%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • Trump: Disappointed if New Fed Chair Does Not Cut Interest Rates

    On April 21, U.S. President Trump stated: If the new Federal Reserve Chair does not cut interest rates, I will be disappointed.

  • Chairman of the Joint Chiefs of Staff Milley States Readiness to Resume Operations

    On April 21, Chairman of the Joint Chiefs of Staff Mark Milley stated that the U.S. is ready to resume operations and can act against Iran at any time. (Axios)

  • Bank of Japan to Maintain Interest Rates in April

    On April 21, according to Nikkei News: The Bank of Japan will maintain interest rates unchanged in April.

  • Iranian Military: Ready to Respond Decisively to 'Enemy's Breach of Promises'

    On April 21, local time, Abdollahi, commander of the Khatam al-Anbiya Central Command of the Iranian Armed Forces, stated that Iran is prepared to respond decisively to the 'enemy's breach of promises.' Abdollahi emphasized that the current Iranian military possesses 'authority, readiness, and comprehensive strategic capabilities.' He noted that the Islamic Revolutionary Guard Corps and other defense forces have demonstrated combat capabilities in relevant operations, putting 'Israel and the United States in a difficult and fatigued position,' forcing them to 'seek a ceasefire.' Abdollahi also stressed that the Iranian armed forces maintain a high level of unity with the government and the people under the supreme leader's unified command, and will respond 'decisively, resolutely, and promptly' to any threats and actions. (CCTV News)

  • Another Iranian Oil Tanker Returns to Iran After Breaking US Blockade

    On April 21, according to CCTV News, maritime intelligence company 'TankerTrackers' reported that a tanker belonging to the National Iranian Tanker Company returned to Iran after unloading approximately 2 million barrels of crude oil in Indonesia, crossing the relevant maritime blockade line. The tanker is currently en route to Iran's main oil export hub, Khark Island, and is expected to arrive on April 22 local time. It is reported that the tanker set sail from Iran in late March, heading towards the Riau Islands of Indonesia.

  • White House: US and Iran on the Verge of Reaching an Agreement

    On April 21, White House Press Secretary Kayleigh McEnany stated in an interview with Fox News on the evening of the 20th that the United States and Iran are on the "verge of reaching an agreement." McEnany remarked, "The US has never been closer to achieving a truly good deal." However, she did not disclose any information regarding the current status of the negotiations. McEnany noted that even if an agreement is not reached, President Trump has multiple options and is not afraid to utilize these measures. Previous actions have demonstrated that Trump is not just "bluffing."

  • Kelp DAO Attacker Transfers 30,800 ETH to Special Address

    On April 21, news emerged that, according to monitoring by PeckShield, the Kelp DAO attacker transferred 30,800 ETH to a special address starting with 0x00000, possibly indicating a destruction action.