Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

IDEX exchange may be suffering some hacks #4595

Closed
danfinlay opened this issue Jun 17, 2018 · 1 comment
Closed

IDEX exchange may be suffering some hacks #4595

danfinlay opened this issue Jun 17, 2018 · 1 comment

Comments

@danfinlay
Copy link
Contributor

danfinlay commented Jun 17, 2018

Following up from this MetaMask subreddit post, where a user says after using IDEX, they had ether stolen.

If you trace where their transaction was stolen to, it goes through multiple accounts, especially being routed through this account, which has many transactions on it of people making similar claims about using IDEX and then losing funds:
https://etherscan.io/address/0xfb9f7f41319157ac5c5dccae308a63a4337ad5d9#comments

After following up with the user, they actually used an IDEX built-in account initially (remember those, from EtherDelta? The ones that got drained all at once in the DNS hack?). After reading a tutorial on MyCrypto about the enhanced security of using MetaMask, the user switched to MetaMask.

To me this resembles an attacker having control of IDEX, and tactfully draining only some accounts, just enough to keep the user outcry minimal. This really emphasizes the need of well-audited, deterministic web apps for things like decentralized exchanges. (Could be improved after merging #4405)

Opening a thread here to see if this story is common. Maybe this should be a reddit post instead, but I don't want to be alarmist, I just want to get a real sense of how common this is, put out feelers for how people might want to respond.

@whymarrh
Copy link
Contributor

Opening a thread here to see if this story is common. Maybe this should be a reddit post instead, but I don't want to be alarmist, I just want to get a real sense of how common this is, put out feelers for how people might want to respond.

Over 1 yr later I think we can close this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants