Weekly Report (Dec-11)


  • Over $46 million was lost in multiple DeFi hacks.
  • Immutable Games collaborates with Amazon Prime Gaming for the new season of Gods Unchained.
  • Futureverse and Reebok collaborate to innovate digital fashion in the Metaverse.
  • Ledger and RTFKT unveil an exclusive digital collectible capsule collection.

Blockchain Hacks

The CKD token on the BNB chain experienced a rug pull, resulting in the misappropriation of approximately $539,000 in funds. The deployer of the token and its related externally owned address removed its liquidity in multiple transactions, causing the price of the token to plummet by over 99%.

Bearn DAO was exploited on the BNB chain due to a smart contract vulnerability, which resulted in a loss of assets worth approximately $769,000. The root cause of the exploit was a vulnerability that allowed the attacker to manipulate token swap ratios and execute a profitable sandwich attack. In this blog, we shared a detailed analysis of the exploit.

Elephant Money was exploited on the BNB chain due to a smart contract vulnerability, which resulted in a loss of assets worth approximately $165,000. The root cause of the exploit is a lack of slippage protection on the token swap. The hacker was able to identify an unverified contract that had the privilege to withdraw funds from the Treasury. The exploiter then called an unprotected function of this contract to force withdraw the funds and make a swap with zero slippage protection.

The TIME token was exploited on the Ethereum Mainnet due to a smart contract vulnerability, which resulted in a loss of 94 ETH, worth approximately $200,000. The root cause of the exploit is a price manipulation attack caused by a public burn issue. Thirdweb had issued a community alert regarding the security vulnerability in one of the most commonly used web-based open-source libraries, following the issue disclosure within the team on November 20, 2023. This disclosure directly relates to the attack experienced by the vulnerable contract.

OpenZeppelin acknowledged Thirdweb’s disclosure of this vulnerability, highlighting an arbitrary address spoofing attack resulting from the improper integration of ERC-2771 and Multicall standards. Investigations showed that this issue affected approximately 515 Thirdweb-deployed tokens on the Ethereum Mainnet, with hackers already exploiting 25. Additionally, the BNB chain hosted 1,276 of these vulnerable tokens. The KyberSwap Exploiter hijacked over $43.35 million by targeting HXA Coin (HXA). Similarly, the Web3Camp protocol on the BNB chain lost about 6.687 trillion 3P tokens, equivalent to $40,000, due to this vulnerability. Active exploitation of this security flaw has led to a collective loss of over $44.65 million across various protocols.

The isolated LST BNB pool of Venus Protocol for liquid staked BNB was exploited due to the Binance Oracle price feed issue, which resulted in a loss of approximately $274,000. The team promptly paused the snBNB market along with two other isolated markets, agEUR and stkBNB, with similar Binance Oracle configurations discovered on those feeds. Other markets remain fully functional and unaffected.

Metaverse, and NFTs

Immutable Games joined forces with Amazon Prime Gaming, ushering in a new era for its critically acclaimed trading game, Gods Unchained. This partnership, coinciding with the game’s much-anticipated second season, Far Horizons, represents a pivotal moment in the gaming landscape. It grants the 200 million subscribers of Prime Gaming access to monthly exclusive rewards in-game, provided they link their accounts. This integration significantly enriches the player experience. Far Horizons brings not only a fresh aesthetic but also introduces groundbreaking gameplay elements, including the Tides of Fate expansion. This expansion offers an array of 142 new cards, nine exclusive in-game-only chained cards, and the cutting-edge manasurge mechanic. Manasurge, a novel feature, allows cards to gain enhanced effects based on the mana spent per turn, adding strategic depth to gameplay.

Futureverse and Reebok are joining forces to redefine consumer engagement in the Metaverse through the introduction of Reebok Impact, a pioneering digital shoe experience. Set to launch in 2024, this initiative will immerse consumers in a world where artificial intelligence, blockchain-powered gaming, and digital wearables converge. Touted as both mind- and heart-bending, Reebok Impact is a testament to Futureverse’s cutting-edge technology and their prowess in creating exceptional digital content. The partnership between Reebok and Futureverse doesn’t end with Reebok Impact. They are poised to broaden their horizons, enhancing functionality, forging integrations, and unveiling new and exciting experiences. This venture marks a significant step in blending fashion with digital innovation, paving the way for a transformative journey in the realm of digital consumer experiences.

Ledger has collaborated with RTFKT to unveil a limited-edition capsule collection, a fusion of innovative design and top-tier security. Central to this collaboration are two exclusive products: the RTFKT x Ledger Nano X Chalk Blade Edition and the RTFKT x Ledger Collector Edition. These products embody a seamless blend of RTFKT’s luxurious aesthetics and Ledger’s acclaimed security expertise. The RTFKT x Ledger Nano X Chalk Blade Edition marries style with security. It boasts a high-quality custom plastic swivel bearing the branding of both Ledger and RTFKT. The design is further enhanced by a matte black soft-touch sleeve, a pristine white device casing, and a unique transparent smoked glass button. Complementing this, the RTFKT x Ledger Collector Edition features two bespoke Ledger Nano X devices. The first is encased in an eye-catching black matte soft-touch sleeve. The second device takes innovation a notch higher, residing in a specially designed vial case by RTFKT.

OnChain Insurance Industry News

Neptune Mutual continues to run their cashback promotion on policy fees for all cover purchases in the Neptunite Marketplace on Arbitrum, with the campaign ending on December 15, 2023.
The monthly town hall meeting providing updates for the month of November was given in Discord on December 6th and was recorded and published on Neptune Mutual’s YouTube channel. Highlights included updates on the increase in social media engagement, growth in the size of the Neptunite community, and increased NPM trading volume and visibility. Since the town hall, Neptune Mutual’s Youtube community has grown to over 2K subscribers, double what it was just a few weeks ago, and the X community has grown to over 31K followers.