Ben Adamsky 💭
@ba
Update on today's incident: We've identified a critical vulnerability in our withdrawal API, where there was an exploit that allowed unauthorized withdrawals to bypass our security checks. We've frozen withdrawing funds on smart wallets until this is fully resolved. Most importantly - all smart contracts, admin wallets, and user smart wallets remain fully secure and uncompromised The root cause was an authentication spoofing technique in our API routes due to architectural constraints within our auth system. We've learned a lot from this exploit and are implementing more robust security measures to prevent a situation like this from ever happening again. All affected users will be refunded this week
10 replies
24 recasts
85 reactions
Tom
@tomkey
Sorry this happened to you guys!! Thanks for responding fast and clarifying
1 reply
0 recast
3 reactions
Ben Adamsky 💭
@ba
Appreciate it, lmk if you have any additional questions or concerns 🙏
0 reply
0 recast
2 reactions