CryptoPotato
CryptoPotato
  • Crypto News
  • Margin Trading
  • Guides
    • Bitcoin & Crypto Guides 101
    • Bitcoin For Beginners
    • Editorials
  • DeFi & NFT
  • Buy
  • Language
  • Crypto News
  • Bitcoin For Beginners
  • Cryptocurrency Guides 101
  • Editorials
  • Bitcoin & Crypto Margin Trading
  • DeFi & NFT News
  • Bitcoin Price Analysis
  • CryptoPotato Crypto Fund
  • Ethereum (ETH) Price Analysis
  • Ripple (XRP) Price Analysis
  • Market Updates
  • Interviews
  • Buy Bitcoin with Card
  • bitcoin
    BTC$27,750.00
  • ethereum
    ETH$1,765.72
    • Market Updates
    • BTC Analysis
    • ETH Analysis
    • XRP Analysis
    • Interviews
    • Opinions
    CryptoPotato
    CryptoPotato
    • Crypto News
    • Margin Trading
    • Guides
      • Bitcoin & Crypto Guides 101
      • Bitcoin For Beginners
      • Editorials
    • DeFi & NFT
    • Buy
    • Language
    • Crypto News
    • Bitcoin For Beginners
    • Cryptocurrency Guides 101
    • Editorials
    • Bitcoin & Crypto Margin Trading
    • DeFi & NFT News
    • Bitcoin Price Analysis
    • CryptoPotato Crypto Fund
    • Ethereum (ETH) Price Analysis
    • Ripple (XRP) Price Analysis
    • Market Updates
    • Interviews
    • Buy Bitcoin with Card
    Home » Crypto News » Hacked Lending Protocol XCarnival Receives $1.9M Worth of Stolen ETH Back

    Hacked Lending Protocol XCarnival Receives $1.9M Worth of Stolen ETH Back

    Author: Arun Srivastav

    Last Updated Jun 27, 2022 @ 11:36

    The hacker used a flaw in its smart contract that showed released NFT as available for collateral to be used for borrowing.

    In a quick-paced development, XCarnival, describing itself as a Metaverse Asset Bank, lost over 3,087 ETH to a hacker and negotiated the return of half of the funds less than 24 hours after the incident. 

    Exploiting a flaw in its smart contract, the attacker used a Bored Ape Yacht Club NFT, which was already withdrawn after being pledged, as collateral to borrow from the platform. The same transaction was repeated several times until a watchdog alerted XCarnival, which promptly paused the operations – smart contracts, lending, and borrowing.  

    Alert from Watchdog

    The platform for which the loss can be much higher was alerted by blockchain security and data analytics company PeckShield. The initial amount used for the attack was 120 ETH that the hackers withdrew from Tornado Cash, PeckShield said. 

    Subsequently, the watchdog provided more details in a series of tweets as to how the hack was pulled off.  

    “The hack is made possible by allowing a withdrawn pledged NFT to be still used as the collateral, which is then exploited by the hacker to drain assets from the pool,” it said in one of its tweets. 

    Nearly 12 hours after the attack, XCarnival asked the hacker to return the stolen funds, offered a 1,500 ETH bounty, and promised exemption from legal action. As per blockchain data, the exploiter accepted the offer after a bounty negotiation that began with 250 ETH and settled at 1,500 ETH. 

    ADVERTISEMENT

    Theft and Scam Prevention

    In a similar incident, Hollywood personality Seth Green’s Bored Ape #8398, stolen in a phishing attack on May 17, was negotiated for the return. Green reportedly paid 165 ETH (approx. $300k) for the NFT to its new owner, who had bought it for $200k in good faith, unaware that it was a stolen one.

    Fred Simian, as Green had named the NFT character, was to be used as the main character in one of his upcoming shows – White Horse Tavern.

    The NFT trade skyrocketed from under $200 million in 2020 to $40 billion in 2021. Consequently, instances of such theft and plagiarism have also increased in this space. Early this month, the CEO of one of the largest NFT marketplaces – OpenSea – Derin Finzer, outlined the need for Trust and Safety investments in areas such as theft and scam prevention, among others. 

    SPECIAL OFFER (Sponsored)
    Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

    PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

    You Might Also Like:

    • BAYC
      Bored Apes Yacht Club Reveals Date for Otherside Meta Project, APE Soars 40% Weekly
    • Nexo_ApeCoin
      Nexo Integrates ApeCoin (APE) Into its Yield Platform
    • BAYC_Floor
      Bored Ape Floor Plunges Below $100K as NFT Prices Collapse
    Tags: Bored Ape Yacht Club (BAYC) Hacking NFT
    Enjoy reading? Share with your friends
    Facebook Twitter LinkedIn Telegram

    About The Author

    Arun Shrivastav
    More posts by this author

    After being in the mainstream print media for over 10 years, Arun has been active in digital media. He joined the crypto industry in 2017 and since then, covering blockchain news. Besides news, he likes to blog about digital marketing. Contact: LinkedIn

  • bitcoin
    BTC$27,750.00
  • ethereum
    ETH$1,765.72
  • Join Our Community

    FacebookTwitter YouTubeTelegram


    Editorials
    Artificial Intelligence & Crypto Guide: Here Are the Top 5 AI Coins

    Artificial Intelligence & Crypto Guide: Here Are the Top 5 AI Coins

    How to Keep Your Crypto Safe, MetaMask Future Plans, and Digital Identities: Talking Wallets With PM Alex Jupiter

    How to Keep Your Crypto Safe, MetaMask Future Plans, and Digital Identities: Talking Wallets With PM Alex Jupiter

    What is Optimism (OP): Guide to One of Ethereum’s Layer-Two Scaling Solutions

    What is Optimism (OP): Guide to One of Ethereum’s Layer-Two Scaling Solutions

    Why ZK-Rollups Are the Future of Ethereum Scaling: Interview with StarkWare PM Gal Ron

    Why ZK-Rollups Are the Future of Ethereum Scaling: Interview with StarkWare PM Gal Ron

    2022 Was Crypto’s Dot Com Bust: Let’s Recap Tech Stocks After 2000 (Opinion)

    2022 Was Crypto’s Dot Com Bust: Let’s Recap Tech Stocks After 2000 (Opinion)

    How Long Will the Ethereum LSD Narrative Last? Talking 2023 Trends with Nansen’s Martin Lee

    How Long Will the Ethereum LSD Narrative Last? Talking 2023 Trends with Nansen’s Martin Lee

    Everything That’s Going on With Pi Network: From Start to Latest Controversial Listing

    Everything That’s Going on With Pi Network: From Start to Latest Controversial Listing

    Join Our Newsletter
    Become a CryptoPotato VIP
    One Weekly Email Can Change Your Crypto Life.
    Sign-up FREE to receive our extended weekly market update and coin analysis report
    We NEVER send spam. You can unsubscribe at any time.
    Invalid email address
    Thanks for subscribing!
    Footer Logo
    About
    Advertise on CryptoPotato
    About Us | Contact Us | Careers
    Editorial Policy
    Terms of service | Privacy Policy | GDPR
    More Sections
    IEO List | Evaluations
    Airdrops
    Scholarship
    Disclaimer
    Disclaimer: Information found on CryptoPotato is those of writers quoted. It does not represent the opinions of CryptoPotato on whether to buy, sell, or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk. Full disclaimer
    © Copyright CryptoPotato 2016 - 2021
    Scroll to top
    One Weekly Email Can Change Your Crypto Life.

    Sign-up FREE to receive our extended weekly market update and coin analysis report

    We never send SPAM. You can unsubscribe at any moment
    Invalid email address
    Thanks for subscribing!