Tapioca DAO breach led to loss of over $4m assets

The crypto space is no stranger to hacks and attacks that has led to the loss of significant amount of funds. Sometimes, users of defi platforms or crypto exchanges become the victims. At other times, operators are targetted. The later is true of Tapioca defi protocol in which significant amount of liquidity was stolen from some of its smart contracts.
Just over the weekend, the Tapioca DAO announced that an attacker has made away with close to $5m in trading liquidity after successfully launching an attack on smart contracts holding Vested TAP tokens. Several vested trading pairs were targeted. At the end a huge amount of Ethereum and USDC was stolen and diverted to wallets belonging to the attacker.
Malicious software led to successful hack
The attack on Tapioca DAO, one that is typical of the defi space, happened just over the weekend. Its a common form of attack where the admin of a defi project is fooled and made to download malicious software that the attacker could use to manipulate vested smart contracts and gain unauthorized access to its liquidity pool. One of the Tapioca admin Rektora fall victim to such trick and downloaded infected software which gave the attacker control over vested token pairs. It resulted in the loss of 591 ETH and very close to $3m USDC.
The Tapioca security teams and other contracted web3 security experts are working round the clock to see how and if funds lost in this attack could be recovered. The attacker has converted all stolen assets into USDT and moved them to a secure wallet. Efforts are being made to secure the defi protocol and ensure that there is no further loss of funds or assets.
The recovery process
Efforts are being made to see if the funds lost could be recovered. While that is ongoing, Tapioca has warned users to be alert to phishing links and other social engineering tactics used by attackers especially after an incident like this one. Below is an announcement made on the protocol's X platform:
We have coordinated and are active in a war room with the necessary individuals and entities to proceed forward, and will be communicating on further steps when the situation is under control. Please be aware of misinformation, scam links, and do not interact with any Tapioca contracts or tokens until further information is provided. Source
Initially as seen above, the security and recovery team advised users not to interact with Tapioca smart contracts in order to contain the size of the loss. Its been more than 48 hours since the event happened. The team having made some progress announced later that users are free again to interact with the protocol's smart contract as everything is secure once again. The platform is open for use by anyone while efforts are then focused fully on trying to recover the funds stolen by the attacker if possible
A $1m bounty for the attacker
Tapioca choose to appeal to the attacker to return the funds stole in exchange for $1m in USDT. This is a popular recovery method that sometimes work for protocols involved in an attack like this. If the attackers responds and return the funds, they can take the bounty without any further actions to be taken against them.
Tapioca announced on X that they have offered the bounty and are still awaiting the response of the criminals who converted the stolen funds to USDT already. It remains to be seen if this method would yield results and lead to retuning and recovery of the stolen funds. Here is what the team updated about contacting the attacker:
Attached below is a link to the official on-chain correspondence from Tapioca DAO Foundation to the hacker responsible for the incident on October 18th, 2024.source
Beware, anyone could be a victim
The crypto space is full of opportunities, but equally there are many criminals lurking around to steal your assets. Phishing links are one of the most popular methods used by attackers. So always double-check to see that you are interacting with links from an official channel. Its important to check the URL again and again so that you do not end up unknowingly releasing keys and passwords to a phishing website.
And just as seen in the above incident, attackers might try to manipulate you into downloading a piece of software that might look genuine. Again, if the person you are interacting with is a stranger or hides their Identity, its better not to download the software. Its best to only download software from official channels approved by the project and not from individuals or third parties. These are easy safeguards to keep criminals away from your hard-earned assets.
Thumbnail from pixabay
Posted Using InLeo Alpha
We've been experiencing bad downvotes for a considerable amount of time and we're seeking answers. We're concerned about the control held by certain entities like Blocktrades, which delegates Hive power to accounts like Buildawhale, and Usainvote
https://hive.blog/hive-167922/@bpcvoter1/we-ve-been-experiencing-bad-downvotes-for-a-considerable-amount-of-time-and-we-re-seeking-answers-we-re-concerned-about-the
https://peakd.com/hive-167922/@bpcvoter2/despite-the-exposure-certain-individuals-continue-their-actions-calling-names-and-revealing-a-childish-attitude-it-s-crucial-to
https://peakd.com/hive-167922/@bpcvoter3/on-hive-the-transactions-between-punkteam-and-gogreenbuddy-raise-many-questions-transactions-don-t-lie-and-maintaining
https://hive.blog/hive-167922/@bpcvoter1/we-must-stop-the-buildawhalefarm-which-is-backed-by-blocktrades
https://peakd.com/hive-158694/@bilpcoinbpc/a-open-letter-to-hive
!LOL !DOOK !BBH !PGM !BEER !ALIVE !GIF !WEIRD !LUV !PIZZA !LOLZ
https://hive.blog/hive-167922/@bpcvoter1/sljqhf
livinguktaiwan (79)in HiveFest • 2 days ago
He would never survive an hour at HiveFest now 🔪🔪🔪
https://hive.blog/hive-106258/@livinguktaiwan/re-slobberchops-skc63a
https://hive.blog/hive-106258/@slobberchops/re-livinguktaiwan-skc5h1
On Hive a significant issue exists with automatic upvotes consistently rewarding the same individuals day in and day out
We want to address the issue of downvoting. It has caused pain to many people, and we want to make sure it doesn't happen again reply to @jacobtothe
On Hive a significant issue exists with automatic upvotes consistently rewarding the same individuals day in and day out
We hope that those who genuinely care about Hive will reconsider their actions, as continuing down this path could inadvertently harm innocent users who are unaware of these issues
lol the Marky mark keeps dreaming
There's been a notable increase in frustration and concern among many users
Reply 2 @crimsonclad You may consider yourself clever
Reply to @crimsonclad
Consider revising the value plan, as it's not providing significant benefits to HIVE
The Value Plan, as it stands, seems to be a one-sided relationship with the HIVE platform, where the benefits are one-way
Actions indeed speak louder than words, a fact we've all observed individuals may talk a good game, a whole lot of shit, but their actions often expose their genuine nature LOL
We consider it unwise to engage in harmful actions, even if you think you can escape the repercussions
https://hive.blog/politics/@jacobtothe/re-bpcvoter1-shjdc8
The Hive Police aka Hivewatchers, are the real heroes of Hive LOL, aren't they?
Feast your eyes on Hive's trending page, what a load of trash
LoL it's the Hivewatchers Hive Police, dishing out orders like a bakery LOL! Folks, do what you want with your Hive power, just as you please. And you, Hivewatchers, downvote away, but remember, judgment day's coming
Harry fam We're just here, laughing at the shenanigans on Hive! Sure, our content's getting downvoted, but hey, it's all part of the game LOL
https://hive.blog/hive-158694/@hivewatchers/shhnhs
adm [-]
meesterboom [-]
steemcleaners [-]
jacobtothe [-]
logic [-]
chekohler [-]
b00m [-]
celestegray [-]
citizensmith [-]
sazbird [-]
technicalside [-]
bagpuss [-]
vxn666 [-]
spaminator [-]
meestemboom [-]
ihal0001 [-]
tillmea [-]
meesterleo [-]
meesterbrain [-]
unclefunker [-]
and 1 more
https://hive.blog/hivewatchers/@bpcvoter/shqkqc 11
Congratulations @fokusnow! You have completed the following achievement on the Hive blockchain And have been rewarded with New badge(s)
Your next payout target is 9000 HP.
The unit is Hive Power equivalent because post and comment rewards can be split into HP and HBD
You can view your badges on your board and compare yourself to others in the Ranking
If you no longer want to receive notifications, reply to this comment with the word
STOP