Cross-Chain DEX Rubic Loses Over $1M in Funds After Hackers Gain Access to Private Keys

Developers suspect the attackers accessed the admin wallet's private keys using malicious software.

AccessTimeIconNov 2, 2022 at 12:09 p.m. UTC
Updated Nov 2, 2022 at 2:48 p.m. UTC
10 Years of Decentralizing the Future
May 29-31, 2024 - Austin, TexasThe biggest and most established global hub for everything crypto, blockchain and Web3.Register Now

Rubic, a service that allows users to swap cryptocurrencies between different exchanges, was exploited earlier Wednesday after attackers gained access to the private keys of an administrator's wallet.

“One of our admin’s wallet addresses was compromised. This wallet managed the RBC/BRBC bridge and staking rewards,” developers said in a tweet during morning hours in Asia. “We suspect it was malicious software that was used to get access to the admin wallet's private keys.”

A private key is a secret number that is used in cryptography, similar to a password. In cryptocurrency, private keys are also used to sign transactions and prove ownership of a blockchain address.

Around 34 million RBC and BRBC tokens were sold on the Uniswap and PancakeSwap exchanges. As such, Rubic continues to work without interruption and all user funds are safe. No contracts were exploited.

The 34 million RBC transferred out by the attackers was worth over $1.2 million at press time. Separately, the attacker's wallet flagged by Rubic in a tweet held over 205 BNB, or just over $65,000, in a BNB Chain wallet and over $205,000 worth of ether in an Ethereum wallet.

RBC prices plunged over 98% in the hours following the attack as the attackers sold all stolen tokens en masse. Prices bounced during European morning hours.

Disclosure

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.

Shaurya Malwa

Shaurya is the Deputy Managing Editor for the Data & Tokens team, focusing on decentralized finance, markets, on-chain data, and governance across all major and minor blockchains.


Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.



Read more about