Thala Labs Recovers $25M After Hack: Detailed Insights

user avatar

by Giorgi Kostiuk

2 years ago


On November 15, 2024, Thala Labs, a decentralized finance protocol on the Aptos blockchain, faced a significant security breach, resulting in $25.5 million in liquidity pool tokens being stolen.

The Attack and Immediate Actions

The hack was due to an isolated vulnerability in its v1 mining contract, allowing the attacker to withdraw funds. Thanks to swift responses and the assistance of law enforcement, the crypto community, and specialized recovery groups, Thala managed to recover $25 million of the stolen funds just six hours after the exploit. All relevant contracts were paused, and $11.5 million in Thala-associated assets, including $9 million in Move Dollars (MOD) and $2.5 million in THL, were frozen. Affected users were informed that their positions would be fully restored without requiring any action.

We are relieved to announce that affected users require no further action, and their positions will be made 100% whole.Thala Labs

Recovery Process and Negotiation

With the help of Seal 911 and Ogle, Thala quickly identified the hacker. A representative of Seal 911 stated that the hacker was tracked down easily due to obvious on-chain links, and the hacker contacted them willingly to negotiate the return of the stolen funds. In exchange for returning the assets, the hacker was given a $300,000 bounty. The stolen funds were returned just hours after the incident.

What is Thala?

Thala Labs offers automated market making and the yield-bearing stablecoin Move Dollar (MOD) within the Aptos ecosystem. Named after Aptos' programming language, MOD is designed to provide liquidity and stable yields for DeFi users. The protocol recently launched ThalaSwap V2, but the hack was due to a vulnerability within the older v1 contracts.

Thala Labs' incident is part of a growing trend in cryptocurrency security threats. The company is undertaking all efforts to rebuild trust and ensure future safety through comprehensive code reviews and audits. Despite success in recovering the stolen funds, incidents like this continue to pose significant risks to decentralized protocols.

Tier I

Sector: #18291

Sealed Hiding Place Room

Resource Cache

Resource Cache

Tier I

Requires 25% Tier Progress to Claim
Meme Cache

Meme Cache

Tier I

Requires 50% Tier Progress to Claim
Equipment Cache

Equipment Cache

Tier I

Requires 75% Tier Progress to Claim

After collecting, hiding places will be stored in your inventory and can be opened with Keys.

Other news

Justin Sun Prize Launched to Transform Scientific Research

chest

The Justin Sun Prize has been established to redefine scientific rewards in the AI era, offering up to $1 million for breakthroughs in fundamental disciplines and machine formal verification.

user avatarKenji Takahashi

bdautomated Releases Verified AI Agent Statistics for 2026

chest

bdautomated releases a comprehensive dataset on AI agent statistics for 2026, tracing 75 widely quoted figures back to their original sources.

user avatarMaria Fernandez

Korea Blockchain Week 2026 Announces Key Sponsors and Speakers

chest

Korea Blockchain Week 2026 has unveiled its partner lineup, featuring major players in the digital asset industry, including Upbit, 0G, BRV, Stable, Tria, and BitGo. The event will take place in Seoul from September 29 to October 1, 2026, and will host key speakers discussing significant shifts in the digital asset industry.

user avatarGustavo Mendoza

Morgan Stanley's Bitcoin Accumulation Boosts Market Confidence

chest

Morgan Stanley has been actively accumulating Bitcoin through the ETF route, amassing approximately 622 million worth of the cryptocurrency this month.

user avatarRajesh Kumar

Microsoft Opens Public Feedback for AI Code of Conduct

chest

Microsoft is inviting public feedback on its draft Code of Conduct for AI models until late October, aiming to refine guidelines before finalizing them for 2027.

user avatarLuis Flores

Microsoft AI Releases Draft Code of Conduct for AI Models

chest

Microsoft AI has published a draft Code of Conduct outlining the expected behavior and limitations of its AI models, inviting public feedback for six weeks.

user avatarMiguel Rodriguez

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.