Loopring, an Ethereum ZK-Rollup protocol, reported on June 9 that some of its smart wallets were exploited for an undisclosed sum.
Following the news, Loopring’s LRC token dropped by approximately 4%, hitting a four-month low of $0.21, according to CryptoSlate’s data.
$5 million lost
Blockchain security firm Cyvers Alert reported that the breach led to the theft of approximately 1,373 ETH, valued at $5 million.
Loopring had previously described its smart wallets as the “most secured wallets” on the Ethereum blockchain because they possess security measures designed to protect against asset theft.
However, the firm explained that its two-factor authentication service was compromised, allowing the malicious actor to initiate a recovery process, reset ownership, and withdraw assets. Loopring stated:
“The attack succeeded by compromising Loopring’s Two-Factor Authentication (2FA) service, allowing the hacker to impersonate the wallet owner and gain approval for the Recovery from the Official Guardian. Subsequently, the attacker transferred assets out of the affected wallets.”
Meanwhile, Loopring said it was working with blockchain security firm SlowMist to determine how its 2FA service was compromised. The team has temporarily suspended Guardian and other 2FA-related operations. It added:
“Loopring is working with law enforcement and professional security teams to track down the perpetrator. We will continue to provide updates as soon as the investigation progresses.”
Smart Wallets
This breach occurs when smart wallets are gaining traction in the Ethereum community.
Over the past year, support for smart wallets has surged following the Ethereum Foundation’s ERC-4337 account abstraction going live on the Ethereum mainnet. This technology allows users to customize their digital asset management.
Prominent figures like Vitalik Buterin and organizations like Coinbase have backed this technology, which is expected to be part of the upcoming Pectra hard fork.
However, decentralization advocate Chris Blec noted that the Loopring incident demonstrates that “smart wallets are not ready for prime-time,” advising users to “stick with properly-secured seed phrases for maximum safety and sovereignty.”
Similarly, Pratik Kala, Head of Research at Liquid Digital Assets, commented:
“Smart wallets are the rave [at the moment] but new attack vectors come with new tech. We’ll get over it over time but be safe and use hardware wallets for [significant assets.]”
Mentioned in this article