Is the Ronin Hacker Looking to Phish the Euler Hacker?
On-chain analysts deem that the Ronin hacker would be attempting to steal funds from the Euler hacker with a suspicious encrypted message.
The developments round the Euler finance exploit took an surprising twist on Tuesday after the Ronin exploiter despatched 2 ETH to the Euler hacker.
#PeckshieldAlert Ronin Bridge Exploiter transferred 2 $ETH to
Euler Finance Exploiter 2 https://t.co/aWkIKnPa57 7 hours ago pic.twitter.com/u81Z543ai1— PeckShieldAlert (@PeckShieldAlert) March 22, 2023
The Ronin exploiter encoded a message within the Ethereum transaction asking him to decrypt it the utilization of a GitHub repository the utilization of the deepest key that controls the stolen Euler funds.
Blockchain security analysts chanced on that the GitHub repository linked within the message contained a security vulnerability, suggesting the Ronin hacker became once attempting to phish the Euler hacker.
“Together with context – the equipment has a know signature malleability direct, so if the Euler exploiter signs a message with the equipment their deepest key shall be compromised,” explained blockchain security firm Dedaub in a tweet.
The repository in query belongs to an encryption and decryption library published by web3 consulting company LimeChain in 2018, forked from an originate-source Ethereum ECIES library. LimeChain denied any connection to the hackers’ actions in a tweet almost at present after.
3) Neither LimeChain, nor @LimeLabsHQ has any connection to these messages and we condemn injurious actors within the condominium.
— LimeChain – Blockchain & Web3 Solutions (@LimeChainHQ) March 21, 2023
“We’ve been constructing decentralized apps and infra since 2018, in hopes for a higher and safer Web, and are originate to serving to affected parties if wanted,” acknowledged LimeChain.
The Euler team spoke back to the Euler hacker with a blockchain message, advising him to “be very careful the utilization of that encryption software program.” The Euler hacker has been in talks with the Euler team through on-chain messages over the last few days, discussing the aptitude return of $191 million rate of stolen crypto restful in his possession.
“We restful wish to impress the factual direct returning funds to the Euler team. Will keep in touch almost at present,” spoke back the Euler hacker in a message almost at present after.
Market contributors are restful undecided on whether or no longer the blockchain messages between the 2 hackers were half of an true strive and steal funds, or if it became once merely two parties striking on a notify. Final week, the Euler hacker despatched 100 ETH to the Ronin hacker’s pockets take care of, creating confusion over ability links between them. One person described the no longer likely collection of events as the “most recoil public hacker-on-hacker.”
What if… the Ronin hacker attempting to phish the Euler hacker is a spurious flag operation to throw us off the scent? 🤔🥸🫠 pic.twitter.com/BsGuT8XcWj
— Demosthenes | demosthenes.eth (@kwiledirects) March 21, 2023
Source credit : unchainedcrypto.com