Ankr successfully patches hack, will reimburse victims and take actions to prevent further attacks

abdelaziz Fathi

DeFi protocol Ankr plans to reimburse its affected users after a hacker managed to exploit a bug in its code that allowed for unlimited minting of its liquid staking token.

The team behind the BNB Chain-based protocol wrote a blog post that described in detail exactly what happened and the primary steps they are taking to proactively prevent attacks from happening in the future. 

Ankr identified the exploit on December 1, which came from vulnerabilities in the smart contract code. Specifically, the malicious actors gained access to the team’s developer private key and altered the smart contract for its BNB liquid staking token (aBNBc). 

The team further explains that the hack allowed the exploiters to deploy a new version of aBNBc smart contract, which gave them the ability to mint about 60 trillion coins while bypassing verification. Then, the attacker swapped the minted aBNBc tokens, which represents a staked version of BNB token, for USDC stablecoin and moved them off Binance chain onto Ethereum and funneled through crypto mixer Tornado Cash. 

According to the post, Ankr estimates the damage to be $5 million worth of BNB across liquidity pools in various DEXes. At this stage, they are identifying liquidity providers that have been affected by the exploit due to the drainage of liquidity pools. Next, Ankr will purchase $5 million worth of BNB and use this to compensate the victims.

“Thanks to the fast actions from the Ankr team and various protocols, we were able to minimize any damage done extremely quickly. Hacks and exploits from bad actors like this are an unfortunate possibility in Web3, even with every attention to detail in security processes – but we were well prepared. Unlike previous events in the space this year, we are doing the right thing by our community and ensuring that this is taken care of immediately with lost funds restored,” said Chandler Song, Co-Founder & CEO at Ankr.

What are the next steps for Ankr?

In an announcement to its community, Ankr emphasized that they will discontinue aBNBc and aBNBb tokens with immediate effect. Instead, new ankrBNB tokens will be minted and airdropped to affected users. This is by far the most important security measure, as the attack solely affected aBNBc, and other tokens were safe. 

To do that, Ankr is currently going through the process of taking a snapshot to airdrop the newly-released ankrBNB tokens to affected users based on the balances they had before the exploit. 

Meanwhile, Ankr alerted all users not to trade aBNBc or speculatively buy it at a discount. After proper identification, they just need to wait for the ankrBNB airdrop, which will be proportional to the amount of aBNBc and aBNBb that pre-hack users held. 

The attack on Ankr was relatively small in comparison with other recent attacks on DeFi projects, which have seen more than $3 billion stolen from various crypto protocols so far in 2022.

While the protocol has been through a few dark days, this is a learning experience. Additionally, this action plan is said to allow Ankr to more rapidly restore value to legitimate token holders while also accelerating the planned migration to an upgraded contract.

Read this next

blockdag

Top 6 Altcoins Under $1: BlockDAG Surges 500%, Followed By SHIB, FLOKI, VeChain, BONK & PEPE

Discover the top 6 altcoins under $1, including SHIB, FLOKI, VET, BONK, PEPE & BlockDAG, which is seeing an incredible boost in its presale momentum.

Retail FX

Italy blocks domains of Vantage, Luno Invest and Crypto Trade

Consob, the Italian securities regulator, has dropped the hammer on yet another number of FX websites it says were illegally promoting trading products in the country. It has contacted Italy’s internet service providers (ISPs), requesting that they block access to all of the sites in question.

Digital Assets

Celsius users consider legal challenge to reorganization plan

A group of creditors from the bankrupt crypto lender Celsius is looking into legal options to challenge the company’s reorganization plan, which they claim unfairly favors certain creditors.

Digital Assets

e-CNY mastermind Yao Qian arrested in corruption probe

The mastermind behind China’s central bank digital currency (CBDC) project is reportedly under scrutiny for suspected “violations of discipline and law,” according to Shanghai Securities News.

Fundamental Analysis, Market News, Tech and Fundamental

Global FX Market Summary: USD Strength, US PCE, Eurozone April 26 ,2024

US inflation data came in hotter than expected, pressuring the Federal Reserve to potentially raise interest rates and causing the US Dollar to rise against the Euro as the Eurozone faces economic uncertainties.

blockdag

BlockDAG Presale Tops $20.7M! Here’s How to Buy BDAG Coins with USDT and Ethereum for Explosive Gains of 30,000x

Early investors are looking at potentially significant returns in its tenth batch at $0.006 per coin.

Retail FX

Exclusive: Prop firm Funded Engineer faces lawsuit from FPFX

Retail trading tech provider FPFX Technologies, LLC (FPFX Tech), has filed a lawsuit against the prop firm Funded Engineer and its associated operatives for alleged breaches of contract.

Market News, Tech and Fundamental, Technical Analysis

USDJPY Technical Analysis Report 26 April, 2024

USDJPY currency pair can be expected to rise further toward the next resistance level 160.00, target price for the completion of the active impulse sequence (C).

<