• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Thala Labs Recovers $25M After Hack: Detailed Insights

user avatar

by Giorgi Kostiuk

2 years ago


On November 15, 2024, Thala Labs, a decentralized finance protocol on the Aptos blockchain, faced a significant security breach, resulting in $25.5 million in liquidity pool tokens being stolen.

The Attack and Immediate Actions

The hack was due to an isolated vulnerability in its v1 mining contract, allowing the attacker to withdraw funds. Thanks to swift responses and the assistance of law enforcement, the crypto community, and specialized recovery groups, Thala managed to recover $25 million of the stolen funds just six hours after the exploit. All relevant contracts were paused, and $11.5 million in Thala-associated assets, including $9 million in Move Dollars (MOD) and $2.5 million in THL, were frozen. Affected users were informed that their positions would be fully restored without requiring any action.

We are relieved to announce that affected users require no further action, and their positions will be made 100% whole.Thala Labs

Recovery Process and Negotiation

With the help of Seal 911 and Ogle, Thala quickly identified the hacker. A representative of Seal 911 stated that the hacker was tracked down easily due to obvious on-chain links, and the hacker contacted them willingly to negotiate the return of the stolen funds. In exchange for returning the assets, the hacker was given a $300,000 bounty. The stolen funds were returned just hours after the incident.

What is Thala?

Thala Labs offers automated market making and the yield-bearing stablecoin Move Dollar (MOD) within the Aptos ecosystem. Named after Aptos' programming language, MOD is designed to provide liquidity and stable yields for DeFi users. The protocol recently launched ThalaSwap V2, but the hack was due to a vulnerability within the older v1 contracts.

Thala Labs' incident is part of a growing trend in cryptocurrency security threats. The company is undertaking all efforts to rebuild trust and ensure future safety through comprehensive code reviews and audits. Despite success in recovering the stolen funds, incidents like this continue to pose significant risks to decentralized protocols.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

chest

Other news

SUI Group Increases Loan to Bluefin, Strengthening DeFi Ties

chest

SUI Group Holdings Limited has expanded its lending agreement with Bluefin, increasing the total loan to 6 million SUI to support Bluewater Labs' acquisition of Suilend.

user avatarLuis Flores

Sui Seal MPC Introduces Hidden Bids for Enhanced AI Trading Security

chest

Mysten Labs has introduced a feature in the Sui Seal MPC system that enables hidden bids for AI trading, enhancing security and reducing risks of frontrunning.

user avatarMaria Gutierrez

Mysten Labs Introduces Sui Seal MPC for Secure AI Transactions

chest

Mysten Labs has launched Sui Seal MPC on the Sui mainnet, enabling autonomous AI agents to execute onchain transactions securely without holding private keys.

user avatarArif Mukhtar

Chainlink Collaborates with Project Pangea to Revolutionize Cross-Border FX Settlements

chest

Chainlink partners with Project Pangea to enhance cross-border FX settlements, aiming to reduce settlement times from T2 to T0 using stablecoins by mid-2027.

user avatarDavid Robinson

SecondFi Suspends Services Due to Critical Wallet Flaw

chest

SecondFi has suspended its services due to a critical vulnerability in its wallet generation software that led to the theft of ADA.

user avatarAndrew Smith

Morgan Stanley's Proposed Solana Trust Filing Sparks Market Interest

chest

Morgan Stanley has amended its S1A filing for a proposed spot Solana Trust, focusing on fees and staking plans.

user avatarJacob Williams

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.