wrETH Post-Mortem and Next Steps

Summary

On July 26 the RocketPool wrETH wrapper was hacked and the entire balance of 4.9079 rETH was taken. All of those funds came from a newly launched PoolTogether wrETH vault. The vault has since been deprecated, and G9 is going to reimburse the victims using our security budget.

Post-Mortem

Trevor from G9 has written a comprehensive breakdown of the hack. Read the post-mortem for more details.

Compensation

This is a very small hack, so we are going to treat it as if it were a critical security issue reported by a whitehat. Our critical pays out at $25k USD, so our security budget is sufficient to cover the losses.

The following ETH payouts will be made:

Address ETH
0xad2d5bDc3C2dD575C0fA8b70B4f9dFc74B5C1590 3.301686649638513375
0x67D9057494e2E1B7361251043843Db3c2ABF8177 0.994826124030549083
0xE1EFd0284B2e12d261466D51f421f2d1e930e121 0.716304764334162263
0xa184aa8488908b43cCf43b5Ef13Ae528693Dfd00 0.298464325708505357
0xacd5443c888301bc2a767db1b11d1c7e5fa98002 0.097366136184205931
0xD66435f40885865f96c834234dFA83EfE2Ebff9F 0.030617104570922403
0xF80A7327CED2d6Aba7246E0DE1383DDb57fd4475 0.010935487577239963
0x3994537274f3fF3eefc413E0D669b05D6446D46b 0.00671064475797638
0x905893f53D0fa232Fc00eaBd5cdb5AC5d57AB18C 0.000617261878788835
0xb1e4f56590cA358548696d9eC161cd16Cc3BB135 0.000000111173733773

Next Steps

The Optimism Foundation generously granted G9 OP tokens to use to incentivize Liquid Staking Tokens on Optimism. We’re going to launch an LST vault, but are currently investigating alternatives to the integration that RocketPool deployed. We will keep the community informed as to our decision.

4 Likes

Thank you, Brendan! Whereas the situation could not be more unfortunate I’m happy it was handled so well.

Thanks for sorting out the reimbursement to all those affected!

2 Likes

Please share this vault hack on x.com. Also I responded to your message there after being banned/blocked elsewhere.

Your shady ways are damaging your believers. I will be making a post sharing our convo because you seem to want to make it about me trying to get money when I offered the same offer as the beginning. To date you have built every thing I shared and you say that I didn’t share anything.
( rightfully so, I chose not to share actual alpha). Users trying to get funded to build is not new and the path you laid out is bs.

Still to date you don’t know what I want to build for pool together and I have constantly tried to get anyone to say what is it. You don’t care about this project and we demand that you stop playing games with people’s life savings. This all feels like an SBF and Celsius falsehood of “we are here to help” as you take and damage others.

I’m immune to your bs and think everyone who has been in crypto more than a month is too. I hope you start being responsible the last 6 weeks of Generation Software’s time here because you left the Dao with a token down 99.9% and you look to pay yourself the rest.

Real founders choose to not take a paycheck when business is bad and you have paid yourself $3 million for V5 over 2 years and still can’t get it right.

There was no issue with the vault or any PoolTogether code. The exploited smart contract in question (wrETH) belongs to Rocket Pool.

Look at Pooltime and Susu for positive examples of builders getting funded.

I can’t follow your accusations here and want to remind you to stay on topic once again. This thread is about the wrETH post-mortem.