2/ The black-hat exploiter began with a seemingly legitimate proposal via the CREATE2 deterministic deployment a week prior to executing their malicious code after the SELFDESTRUCT function on TC governance.
https://t.co/Q0NbHKRNGi
— Portal Gate (@portalgateme)
May 22, 2023
https://t.co/Q0NbHKRNGi
— Portal Gate (@portalgateme)
May 22, 2023
Twitter
The attacker waited for the legitimate proposal to pass before they called the self-destruct function: https://t.co/5I2eMDyCcp
Self-destruct was typically used in TornadoCash proposals to clean up the proposal contract after execution.
Self-destruct was typically used in TornadoCash proposals to clean up the proposal contract after execution.
3/ Thereafter, Tornado Cash’s on-chain governance effectively ceased to exist due to the overwhelming grant of 1.2M votes, taking control of the withdrawal, function, and overall function of the pool.
https://t.co/TEiDio9DDZ
— Portal Gate (@portalgateme)
May 22, 2023
https://t.co/TEiDio9DDZ
— Portal Gate (@portalgateme)
May 22, 2023
4/ This is evident with the immediate sale of the TORN token on the open market after they utilised the emergencyStop function to grant themselves fake votes.
I.https://t.co/zpBVfvupoO
II.https://t.co/Cd7jf4Opdr https://t.co/s9GqlzZO4m
— Portal Gate (@portalgateme)
May 22, 2023
I.https://t.co/zpBVfvupoO
II.https://t.co/Cd7jf4Opdr https://t.co/s9GqlzZO4m
— Portal Gate (@portalgateme)
May 22, 2023
openchain.xyz
Transaction Tracer
View and trace EVM transactions
5/ Tracing the transaction, approximately 10k $TORN has been compromised, with more potentially under the control of the black-hat exploiter.
https://t.co/iu32RNfpJv
— Portal Gate (@portalgateme)
May 22, 2023
https://t.co/iu32RNfpJv
— Portal Gate (@portalgateme)
May 22, 2023
openchain.xyz
Transaction Tracer
View and trace EVM transactions
6/ So far the exploit is limited to the control of TORN tokens within the governance pool - though researchers have reason to believe that the Classic Router is potentially compromised.
— Portal Gate (@portalgateme)
May 22, 2023
— Portal Gate (@portalgateme)
May 22, 2023
Twitter
6/ So far the exploit is limited to the control of TORN tokens within the governance pool - though researchers have reason to believe that the Classic Router is potentially compromised.
7/ For anyone keen on seeing the bird’s eye view of what exactly happened, @blocksecteam tweeted an encompassing function map to understand the current situation for $TORN holders:
https://t.co/UWM0BCCDc8 https://t.co/euycTjnYmW
— Portal Gate (@portalgateme)
May 22, 2023
https://t.co/UWM0BCCDc8 https://t.co/euycTjnYmW
— Portal Gate (@portalgateme)
May 22, 2023
8/ Furthermore an in-depth transactional analysis by the wonderful team at @slowmist_team shows and confirms @blocksecteam’s findings:
https://t.co/aHi1MOjrAj
— Portal Gate (@portalgateme)
May 22, 2023
https://t.co/aHi1MOjrAj
— Portal Gate (@portalgateme)
May 22, 2023
Twitter
Brief Analysis of TornadoCash Governance Exploit
On May 20, 2023, @TornadoCash suffered a governance attack, in which exploiters took control of the governance of TornadoCash by executing a malicious proposal.
Let's see how it happened:
Exploiters first…
On May 20, 2023, @TornadoCash suffered a governance attack, in which exploiters took control of the governance of TornadoCash by executing a malicious proposal.
Let's see how it happened:
Exploiters first…
9/ Tracking some notable addresses that the hacker could potentially control:
https://t.co/3FswPFJvkI
also highlighting this address:
https://t.co/3S6rTnU4Vi
— Portal Gate (@portalgateme)
May 22, 2023
https://t.co/3FswPFJvkI
also highlighting this address:
https://t.co/3S6rTnU4Vi
— Portal Gate (@portalgateme)
May 22, 2023
Twitter
Tornado[.]Cash Governance Attack
We have identified some notable voter addresses.
Is it possible for the Tornado[.]Cash Governance Exploiter to have control over some addresses in them?
An voter address
https://t.co/4m77ts5E9x
We have identified some notable voter addresses.
Is it possible for the Tornado[.]Cash Governance Exploiter to have control over some addresses in them?
An voter address
https://t.co/4m77ts5E9x
10/ In addition, @samczsun highlighted a potential exploit on the #tornadocash Nova by proxy, effectively allowing the black-hat to DRAIN ALL $ETH in the pool via contract upgrades.
TORN Contract:
https://t.co/9vu6ISVmBc
— Portal Gate (@portalgateme)
May 22, 2023
TORN Contract:
https://t.co/9vu6ISVmBc
— Portal Gate (@portalgateme)
May 22, 2023
Gnosis Chain Blockchain Explorer
Contract Address 0xd692fd2d0b2fbd2e52cfa5b5b9424bc981c30696 | GnosisScan
The Contract Address 0xd692fd2d0b2fbd2e52cfa5b5b9424bc981c30696 page allows users to view the source code, transactions, balances, and analytics for the contract address. Users can also interact and make transactions to the contract directly on GnosisScan.
11/ So what now? Currently, the black-hat just proposed a new proposal, effectively attempting to “restore” confidence within the governance contract:
https://t.co/GdnhzypkqB
— Portal Gate (@portalgateme)
May 22, 2023
https://t.co/GdnhzypkqB
— Portal Gate (@portalgateme)
May 22, 2023
12/ Time will tell (proposal deadline as of 26/05/23 11:53PM GMT) whether governance will be restored, but one thing is for sure - Security is paramount.
— Portal Gate (@portalgateme)
May 22, 2023
— Portal Gate (@portalgateme)
May 22, 2023
Twitter
12/ Time will tell (proposal deadline as of 26/05/23 11:53PM GMT) whether governance will be restored, but one thing is for sure - Security is paramount.
13/ As we’re building a compliant privacy solution at Portal Gate, to ensure that we will not experience the same exploit, our on-chain governance will potentially deviate from @tornadocash’s CREATE2 function.
https://t.co/NPhQfOGgui
— Portal Gate (@portalgateme)
May 22, 2023
https://t.co/NPhQfOGgui
— Portal Gate (@portalgateme)
May 22, 2023
14/ This also includes revisiting the requirement to separate ownership of the pool contract and governance contract, ensuring insulation of funds between Governance and TVL deposits.
Refer back to tweet 9/ from this thread.
— Portal Gate (@portalgateme)
May 22, 2023
Refer back to tweet 9/ from this thread.
— Portal Gate (@portalgateme)
May 22, 2023
Twitter
14/ This also includes revisiting the requirement to separate ownership of the pool contract and governance contract, ensuring insulation of funds between Governance and TVL deposits.
Refer back to tweet 9/ from this thread.
Refer back to tweet 9/ from this thread.
15/ To top it all off, we are rooting for the @tornadocash governance team and community as we build together for a better privacy-centric future.
Read more about Portal Gate’s two core product components:
https://t.co/CZqmwXrsfb
— Portal Gate (@portalgateme)
May 22, 2023
Read more about Portal Gate’s two core product components:
https://t.co/CZqmwXrsfb
— Portal Gate (@portalgateme)
May 22, 2023
Medium
Portal Gate’s Two Core Product Components
The use of blockchain technology has opened up new possibilities for financial transactions, but it has also created new challenges when it…
New initiatives are being implemented in our Discord. If you haven't joined us yet, make sure you join now to be a part of the "🌟level-up" community.
As everything comes together, we are also making further plans to deliver our promise to reward early #portalgateme users.
— Portal Gate (@portalgateme)
May 23, 2023
As everything comes together, we are also making further plans to deliver our promise to reward early #portalgateme users.
— Portal Gate (@portalgateme)
May 23, 2023
Twitter
New initiatives are being implemented in our Discord. If you haven't joined us yet, make sure you join now to be a part of the "🌟level-up" community.
As everything comes together, we are also making further plans to deliver our promise to reward early #portalgateme…
As everything comes together, we are also making further plans to deliver our promise to reward early #portalgateme…
Building a compliant privacy solution for users to transact with enhanced privacy and anonymity, as well as meeting compliance requirements. https://t.co/O9iFtV0RNV
— Portal Gate (@portalgateme)
May 23, 2023
— Portal Gate (@portalgateme)
May 23, 2023
Twitter
@portalgateme got dis. privacy, security, compliance 🫡
If you missed our 101 about Portal Gate:
https://t.co/qM98TcRXWU
— Portal Gate (@portalgateme)
May 23, 2023
https://t.co/qM98TcRXWU
— Portal Gate (@portalgateme)
May 23, 2023
Medium
What is Portal Gate?
Portal Gate is a privacy solution powered by a zero-knowledge compliance oracle. It serves as a means for DeFi users to move their assets…
Check out our latest Portal Gate video🔥project pitch at the ScalingX Demo Day
https://youtu.be/cF7poMjGclc
https://youtu.be/cF7poMjGclc
YouTube
ScalingX Demo Day: Introducing Portal Gate
Watch an exclusive video recording of Portal Gate's presentation at the ScalingX Demo Day. In this video, we take the audience through Portal Gate's pitch deck and product features directly on our testnet.
------------
Join the #portalgateme community:…
------------
Join the #portalgateme community:…
RT @jemma_xu: Great chatting with @maxparasol @Cointelegraph on the compliant and private defi stack we are building at @portalgateme with darkpool at its core https://t.co/lVTsTwp5dJ — Portal Gate (@portalgateme) Jun 9, 2023
June 09, 2023 at 02:35PM
via Twitter https://twitter.com/portalgateme
June 09, 2023 at 02:35PM
via Twitter https://twitter.com/portalgateme
Twitter
Trading in a competitive market can be daunting and Portal Gate understands the need to keep those trades secret, yet compliant.
In the article by @maxparasol about building safe and legal privacy solutions,@Cointelegraph, @jemma_xu talks about decentralized…
In the article by @maxparasol about building safe and legal privacy solutions,@Cointelegraph, @jemma_xu talks about decentralized…
👍1
RT @chiraagreythorn: Lights out, trades on! Dark Pool trading is on its way to DeFi. 🔥 https://t.co/li4WaNUqvo — Portal Gate (@portalgateme) Jun 9, 2023
June 09, 2023 at 02:35PM
via Twitter https://twitter.com/portalgateme
June 09, 2023 at 02:35PM
via Twitter https://twitter.com/portalgateme
Twitter
Trading in a competitive market can be daunting and Portal Gate understands the need to keep those trades secret, yet compliant.
In the article by @maxparasol about building safe and legal privacy solutions,@Cointelegraph, @jemma_xu talks about decentralized…
In the article by @maxparasol about building safe and legal privacy solutions,@Cointelegraph, @jemma_xu talks about decentralized…