Bitfinex, Binance thwart massive XRP heist

abdelaziz Fathi

Tether’s sister crypto exchange, Bitfinex, faced an attempted exploit leveraging a feature of the XRP Ledger network. CEO Paolo Ardoino confirmed on X that the exchange successfully thwarted this attempt.

The incident involved an apparent transaction of nearly $15 billion worth of XRP, which is close to half of the token’s $31 billion market capitalization. However, the actual transfer was only a few cents worth of XRP and failed due to insufficient liquidity in the sender’s account.

In addition to Bitfinex, the attacker also attempted a similar exploit on Binance with a transfer of 58.9 billion XRP, which also failed.

The attempted exploit, known as a “partial payments exploit,” was initially detected when the blockchain tracking account Whale Alert reported a transaction of 25.6 billion XRP from an unknown wallet to Bitfinex. The aim of the exploit was to deceive Bitfinex into recognizing the transfer as legitimate, paving the way for a hacking attempt.

Ardoino explained that Bitfinex’s systems identified the transfers as a “partial payment,” a feature of the XRP Ledger that allows a payment to be successful by reducing the received amount. He added that the attack did not succeed because Bitfinex properly processes the ‘delivered_amount’ data field.

Partial payments are designed to facilitate the return of payments without additional costs. However, they are recognized as a potential attack vector. XRP Ledger transactional documents warn that if a financial institution’s integration with the XRP Ledger does not account for the possibility of partial payments, malicious actors might exploit this to siphon funds.

The exploit hinges on the assumption that the targeted company’s system might only read the amount field of an XRP transaction, which is set to a high amount, while the exploiter sends a much lower amount indicated in another transaction field, aiming to be credited for the higher amount.

Whale Alert later retracted its initial post, stating that there was an issue with reading the Ripple node response correctly, leading to some incorrect posts.

Bitfinex was hacked in 2016 to the tune of 119,756 BTC, which was worth $72 million at the time of the hack but is now equivalent to more than $5 billion given the inflation in BTC prices.

In terms of how the hack happened and the identity of hackers themselves, it’s still pretty vague despite indicting two Israeli brothers as partially responsible for the attack. All we know is that Bitfinex’s multi-signature accounts were somehow compromised, and the exchange distributed losses amongst all users to the tune of 36% of their balances.

Read this next

Retail FX

Weekly Roundup: Darren Robinson fined $11M, Binance’s CZ walks free in August

Welcome to our weekly roundup, where we dive into all the latest buzz in the Forex, Fintech, and cryptocurrency scenes. We’ve got you covered with a rundown of the week’s top events and trends in these dynamic sectors, so you can stay in the know and ahead of the game.

Chainwire

Sui Turns One: Debut Year of Growth and Tech Breakthroughs Puts Sui at Forefront of Web3

In the build-up to its launch in 2023, the chatter around Sui reached a level of excitement that has not been matched by any chain that has launched since. The first anniversary of Sui represents a culmination of the remarkable milestones achieved by the network in its first year.

Digital Assets

Coinbase reports Q1 net income at $1.17 billion

Coinbase Global reported strong first-quarter earnings and revenue, thanks in part to a surge in cryptocurrency trading activity triggered by the introduction of the first U.S.-listed exchange-traded funds (ETFs) tracking bitcoin in January.

Digital Assets

Tether increases surveillance of USDT transactions on secondary markets

Tether, the issuer of the USDT stablecoin, has inked a partnership with blockchain surveillance company Chainalysis to monitor its token transactions on secondary markets.

Retail FX

Saxo Bank reports strong trading volumes for FX, commodities in April

Danish multi-asset brokerage, Saxo Bank has reported an increase in trading activities in April 2024. The bank’s clients traded an average daily volume (ADV) of $4.5 billion, up 9.8% from the previous month, but was down 12% year-over-year from $5.1 billion in April 2023.

blockdag

BlockDAG Launches New Payment Options as Presale Tops $22.4M Amid Polygon’s New Partnership & Option2Trade’s Emergence as Cardano Rival

Following the recent release of a moon-based keynote teaser, BlockDAG (BDAG) has announced 10 new payment methods to further facilitate its DeFi services.

Fundamental Analysis, Market News, Tech and Fundamental

Global FX Market Summary: Dollar Weakness, Fed,Euro May 3 ,2024

Weak US jobs data triggered USD sell-off as investors bet on slower Fed rate hikes. This, along with Europe’s surprising economic strength, boosted the Euro.

Fundamental Analysis, Market News, Tech and Fundamental, Technical Analysis

Ethereum Technical Analysis Report 3 May, 2024

Ethereum cryptocurrency can be expected to rise further toward the next resistance level 3340.00 (which stopped the previous minor impulse wave 1 at the end of last month).

Digital Assets

Dorsey’s Block ramps up Bitcoin holdings to $4.7 billion

Block, the payments firm led by CEO Jack Dorsey, has laucnhed a dollar cost averaging (DCA) program to expand its bitcoin holdings, leveraging 10% of its monthly bitcoin-related gross profit for additional bitcoin purchases throughout 2024.

<