SushiSwap‘s token launch platform MISO suffered a supply chain attack yesterday that drained 864.8 ETH from the ‘Jay Pegs Auto Mart’ token auction contract.
The exploit was first identified by Sushi’s CTO Joseph Delong on September 17th, who tweeted out a link to the transaction that drained the funds from the protocol.
A stressful day for Sushi and MISO ends well for token holders
According to Delong, an anonymous contractor managed to inject malicious code into the MISO front end, replacing the original contract for the Jay pegs Auto Mart token auction with a personal Ethereum address. A total of 864.8 ETH has been transferred to the address, but no other auctions have been affected by the exploit.
In a series of since-deleted tweets, Delong said that Sushi had “reasons to believe” the attacker was eratos1122, a pseudonymous developer who worked with Sushi and other DeFi projects such as Yearn.Finance. He shared a document showing a trail of transactions linked to the hac
Źródło: https://cryptoslate.com/hacker-returns-865-eth-stolen-from-sushis-token-launch-platform-miso/