Ordinals Finance rug pulls for at least $1 million

Ordinals Finance was a short-lived project, emerging in late February with promises to help build out a defi ecosystem on the Bitcoin blockchain.

On April 24, the project developer withdrew 256 million OFI tokens and swapped them to ETH worth around $1 million. They then laundered the funds through the Tornado Cash crypto mixer. The project creator deleted the project's Twitter account and took down its website.

"First BRC-20 wallet" UniSat launches, is immediately exploited

Over on the Bitcoin blockchain, people are abuzz over the launch of "BRC-20": a similar concept to the ERC-20 token on Ethereum that allows people to create their own tokens. The standard, which first emerged in early March, is built atop the controversial Ordinals inscription technique that was developed in January. Coins including $ORDI, $PEPE, and $MEME have been created on a blockchain that previously only supported the Bitcoin token.

Not everything has gone smoothly, though. As developers rushed to release wallets to support these new tokens, the UniSat wallet claimed to be the first. However, shortly after it launched, the developers made the Chrome extension inaccessible. They later revealed that the code had contained a vulnerability that exposed it to double-spend attacks. "Currently, we have preliminary investigation results, and out of all 383 transactions, 70 transactions have been identified as affected," they wrote.

It's not yet clear how much was stolen, but the UniSat team promised to compensate affected users. They later tweeted that they had determined the identity of the thief, though the funds have not yet been returned.

€1.5 million stolen in celeb-backed French NFT rug pull that promised to make a movie called Plush

A 3D rendering of a brown fuzzy teddy bear, sitting, wearing a pink and zebra-print suit and hat, holding a spiral lollipopPlush #1253 (attribution)
Around 770 people were convinced to spend a combined almost €1.5 million (~$1.66 million) on NFTs of teddy bears, which sold for around €1,250 each (~$1,380). Buyers were told they would become "co-producers" of the Plush animated film, which would star Kev Adams and other French comedians as voice actors. Adams led the promotion of the NFT project, along with a mysterious figure called "Fabi". Other French celebrities and influencers were also involved in touting the project, and Bella Thorne and Amaury Nolasco were listed on the site as "US voices" for the project.

The NFT buyers — er, "co-producers" — were promised credit in the film credits, voting rights on the script, and a split of 80% of the profits. "Although there is nothing guaranteed, on average, you will make six to seven times what you put in 24 months. Which is huge, when you think, you go to the Caisse d'Epargne, a traditional bank, and you make less than 1% in the year," said one promotional video.

A report from French investigative newspaper Mediapart discovered that the project was backed by a Dubai-registered company called "Illuminart", which played on confusion between its name and that of the France-based Universal Studios subsidiary Illumination. An Illuminart marketing campaign even used Illumination titles, such as The Lorax, Minions, and Despicable Me, and their box office proceeds to suggest Plush buyers were in for a 516% profit.

Meanwhile, the project has gone silent, and its Twitter account last posted in September 2022. NFTs are no longer offered for sale on the official project website, and Illuminart's business license has expired.

Kyiv Post alleges misappropriation of funds by Ukraine DAO

The Ukraine flag2,258 ETH (~$4.2 million at today's prices) was raised via the sale of an NFT of the Ukraine flag (attribution)
Ukraine DAO is a project that emerged shortly after the Russian invasion of Ukraine, aiming to raise cryptocurrency funds to support Ukrainians. Despite the name, it is not a DAO in the typical sense where token holders have voting rights in the project. The initiative has raised millions in donations, and at least $5 million has gone to the Ukrainian government or legitimate charities. The group's website claims $7 million has been donated in total.

However, the Kyiv Post has recently been asking questions about the organization. Earlier in April, the newspaper published an article claiming that the group had fabricated its claims that it was supported by Ukrainian governmental bodies. Now, they've published another article claiming that at least $500,000–$700,000 of funds seem to have been misappropriated.

One point of contention has been that the organization claims that 100% of money raised is donated, but in reality the project leader Alona Shevchenko takes a $5,000/month salary. This led to a split between Shevchenko and Pussy Riot's Nadya Tolokonnikova, who had once been active in promoting Ukraine DAO.

The Kyiv Post has raised questions about other transactions from the Ukraine DAO wallet, which went to other leaders of the project, or to centralized exchanges.

Shevchenko a London-based Ukrainian, who has in the past led the FreeRossDAO — a project to raise funds to support Ross Ulbricht, the jailed creator of the crypto-powered darknet Silk Road marketplace. Shevchenko's most recent project is Iran DAO, which claims to support "Iran's women-led revolution".

Blur NFT platform bug allows old bids to be accepted

The Blur NFT marketplace appeared to become vulnerable to a bug in which old, canceled bids could still be accepted. This meant that people who had placed bids on NFTs when they were selling for higher prices, then canceled them, suddenly found those purchases going through — in some cases on NFTs that were selling for considerably less.

Blur disabled bid acceptance functionality while investigating the bug. Amusingly, this led people to begin placing huge bids they knew couldn't be accepted in order to farm Blur points, some kinds of which are awarded based on bids rather than purchases.

It's not clear how much money was lost due to the bug, but Blur cofounder "Pacman" announced that "any losses will be refunded once the issue is resolved".

Crypto researcher identifies massive wallet draining operation

Crypto researcher Tayvano posted a Twitter thread about a massive, mysterious wallet draining operation that has siphoned more than 5,000 ETH (~$9.88 million at today's prices) as well as other tokens and NFTs from wallets across more than eleven blockchains since December 2022. The operation appears to target more sophisticated crypto users, but the mechanism of attack is unclear. The researcher hypothesized that "someone has got themselves a fatty cache of data from 1+ yr ago & is methodically draining the keys as they parse them from the treasure trove", but emphasized that that was only speculation.

Co-founders of company best known for Bella Hadid NFTs begin $77 million court battle against each other

3-D artwork of a humanoid robot shaped like a woman, all white with a red circle on the chest, wearing a bomber jacket with "Japan" on the arm. The robot has Giga Hadid's face, which is wearing a futuristic visor and earphones. The background is the Japanese flag.A "Cy-B3lla" NFT (attribution)
Krzysztof Gagacki and Edmond Truong are co-founders of Rebase.gg, some sort of augmented reality app where people go hunting for NFTs. They're best known for helping to create a "Cy-B3lla" NFT collection with model Bella Hadid, which launched in mid-2022. Speaking about skepticism of celebrity NFT projects to Vogue in June 2022, Hadid said, "Where that skepticism comes from is the people who just want to have a money grab. To me, it’s so much bigger than that. I want it to be a collective. It’s not a one-stop shop—this is a real passion."

Although the project promised to provide ongoing access to Bella Hadid and various other perks, the project website has already dropped offline, the Twitter account hasn't posted since October 2022, and the Discord is a ghost town save for occasional questions about whether the project is dead. Hadid made $1.5 million for her involvement in the project.

Things at Rebase seem to have devolved, because now Gagacki has filed suit against Truong, alleging that he "has gone rogue". The suit alleges that Truong tried to oust Gagacki from the company, stole around $2 million from a shared wallet, and damaged Gagacki's reputation. In particular, Gagacki is concerned that Truong is attempting to launch the project on the Arbitrum network without Gagacki's involvement, and that tokens minted there "could reach many times over the Rebase app's last round valuation of $150,000,000" without being shared with Gagacki.

Altogether, Gagacki is claiming damages of no less than $77 million, representing the stolen funds, the value of the app, and the profits from the possible Arbitrum deal.

SEC charges Bittrex with operating an unregistered exchange

Several weeks after Bittrex announced it would be winding down its US operations by the end of April, citing the US "regulatory and economic environment", the SEC filed charges against the company and its co-founder and former CEO William Shihara for operating an unregistered national securities exchange, broker, and clearing agency.

The complaint also alleges that Bittrex and Shihara had coordinated with token issuers to dodge potential SEC action by having them remove public "problematic statements" predicting price, describing an expectation of profit, or describing offerings in terms of investments.

Hundred Finance exploited for $7.4 million

An attacker was able to manipulate the exchange rate between tokens and their interest-bearing equivalents on the Hundred Finance system on the Optimism layer-2 network, ultimately siphoning around $7.4 million from the project.

Hundred Finance announced that they were trying to communicate with the attacker to try to convince them to return some of the funds.

This was not the first exploit to impact Hundred Finance: in March 2022, both Hundred Finance and Agave Finance were targeted with a flash loan attack by a hacker who stole a total of $12 million from the two projects.

Bitrue crypto exchange hacked for $23 million

The Singapore-based Bitrue crypto exchange suffered a hack on April 14 in which attackers siphoned tokens including Ethereum, Shiba Inu, and MATIC (the token for the Polygon network). Altogether the stolen funds were estimated at around $23 million.

Bitrue didn't release details on how the attack had been achieved, but explained that one of their hot wallets had been impacted. They announced that they would be pausing withdrawals for several days as they investigated the incident, and that they would be compensating affected users.

No JavaScript? That's cool too! Check out the Web 1.0 version of the site to see more entries.