Crypto News
7 months ago

TrueUSD’s Security Breach Sparks Concerns Over Private Key Compromise

Wayne Jones Oct 23, 2023 19:04
Did TrueUSD fully disclose the security breach? ChainArgos suggests a complex situation with TEURO using TrueUSD's private keys.

According to ChainArgos, a blockchain intelligence firm, the situation surrounding TEURO has become increasingly complex. TrueUSD, the stablecoin company responsible for currencies like TUSD and TGBP, has publicly stated that they have no association with TEURO. However, it is undeniable that the TEURO contract was deployed using one of TrueUSD’s private keys, ChainArgos says.

TrueUSD confirmed a security breach as of the latest September 18, 2023 update. Considering that TEURO was deployed ten days prior, it raises a compelling hypothesis, according to the blockchain firm.

TrueUSD’s Private Key Vulnerability Exposed

ChainArgos argues that an entity appears to possess some of TrueUSD’s private keys, which suggests that TrueUSD may not have fully disclosed the extent of the security breach.

Adding to the complexity is the curious case of TUSD minting. Notably, Justin Sun managed to mint a staggering $850 million worth of TUSD three days before the acknowledged hack.

ChainArgos said it is reasonable to consider that the reserves of TUSD, namely the bank accounts, might have been compromised by someone with access to the project’s private keys, which warrants scrutiny and investigation.

A user, @clickityclack5, pointed out that stealing money from a bank using private keys is impossible. They believe the stability of the peg will be tested in the upcoming days or weeks, and that will be the only way to assess the situation truly.

However, ChainArgos responded by emphasizing that TUSD has a connection to the bank in ways that most tokens aren’t. It could have significant implications if one successfully executes that crucial final wire transfer using compromised private keys.

Moreover, it’s crucial to remember that the hacker compromised private keys and individuals’ bank information and identification in this situation. Combined, these elements provide a substantial foundation for potential harm, particularly if TrueUSD opts to conceal the incident rather than report it, ChainArgos said.

TrueUSD’s Security Dilemma

Customers undergo stringent KYC/AML checks and possess predefined limits on minting and redemption. However, ChainArgos says if a malevolent entity gains access to TrueUSD’s private keys, the established limits might prove futile, potentially compromising the stability of the coin and the safety of customer funds.

Zachxbt, a blockchain sleuth, has come in support of the report, saying that if it is indeed the case that TEURO was not intentionally created as stated, it would suggest a potential compromise of the deployed private key, especially considering that the same entity responsible for deploying TUSD also deployed the TEURO contract.

The subsequent actions involving TEURO tokens add an intriguing layer to the situation: 0x465 transferred 2 million TEURO to 0x9132, which then facilitated the bridging of 13 ETH to Arbitrum and subsequently back to the Ethereum mainnet, ultimately ending up at 0x472. Notably, 0x472 also utilized the official TrueAUD deployer to establish a TrueChineseYuan contract within this transaction hash.

Share This Article
Wayne Jones

Wayne is a dynamic part-time trader with an impressive eye for detail. His passion for understanding financial systems has led to an intriguing interest in blockchain technology, and he enjoys exploring and writing about cryptocurrencies. Possessing a keen intellect and diligent work ethic, he stays up-to-date on the latest industry trends, regularly sharing his insights in articles and professional presentations.