White Hat Hacker Recovers 80% of $2.26M Stolen in Foom Cash Exploit
Summary
Foom Cash, a decentralized lottery protocol, suffered an exploit resulting in the loss of $2.26 million due to a "fatal deployment oversight" involving a missing command-line interface step during its Phase 2 trusted setup, which allowed an attacker to use forged proofs.
White hat hacker Duha identified the vulnerability and secured $1.84 million (81% of the stolen funds) on the Base chain before malicious actors could fully exploit them, while Decurity managed recovery efforts on Ethereum. Foom Cash rewarded Duha with a $320,000 bounty and Decurity with a $100,000 security fee.
This incident highlights the increasing importance of ethical hackers in Web3 incident response, following other notable efforts like the SEAL team established by Samczsun, which actively investigates hack-related incidents.
(Source:Cointelegraph)