Foom.Cash loses $2.26 million due to zkSNARK vulnerability

ETH-3.99%

Foom.Cash security protocol, built on Ethereum, was recently exploited due to a cryptographic verification vulnerability, causing estimated damages of $2.26 million. The attack affected contracts on both Ethereum and Base, resulting in the loss of over 24.28 trillion FOOM tokens. A transaction on Base caused a loss of approximately $427,000, while transactions on Ethereum worth $1.83 million are believed to be “white-hat” efforts to recover assets.

According to GoPlus Security, misconfigured verification keys allowed attackers to impersonate zkSNARK proofs. Certik and BlockSec described this as a “copycat” attack similar to the previous Veil Cash incident. Although promoted as an upgrade of Tornado Cash, Foom.Cash has not issued an official response or remediation plan.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

India’s Central Bureau of Investigation arrests cross-border human trafficking suspects, involving alleged deception of citizens into participating in crypto scams

The Central Bureau of Investigation in India has arrested a suspect named Sunil Nellathu Ramakrishnan, accusing him of serving as a coordinator in a trafficking network related to Southeast Asian online scams. This network lured Indian citizens to Myanmar to participate in scam activities, and the CBI has collected relevant digital evidence, with the investigation still ongoing.

GateNews26m ago

Circle Reverses KYT Freeze on 500 Casino and Whale USDC Wallets

Circle has unfrozen two hot wallets linked to 500 Casino and a crypto whale after a compliance freeze blocked user withdrawals at a centralized exchange. The lack of transparency regarding the initial freeze raises concerns about centralized control over assets.

LiveBTCNews3h ago

Resolv Burns 46M USR After $80M Exploit, Wipes Out Illicit Supply in Major Recovery Push

Key Takeaways: Resolv burned and put about 46 million USR (57%) of illegal supply to its blacklist There is no hacker-related wallet which can transfer or swap USR One of the measures is to upgrade contracts with coordination efforts to restrict impacts of the exploitation After the recent

CryptoNinjas13h ago

Circle Lifts KYT Freeze on Wallets Tied to 500 Casino

The crypto space is once again debating control and transparency after blockchain investigator ZachXBT revealed a fresh update involving Circle. The company has now unfrozen two USDC wallets tied to 500 Casino and a user known as “Whale.” Together, the wallets held more than $330,000. This move

Coinfomania14h ago

Husband accused of his wife stealing 2,000-plus bitcoins! Judge: the plaintiff has a very high chance of winning

The UK High Court recently heard a case involving the theft of Bitcoin, where the plaintiff Ping Fai Yuen accused his estranged wife Fun Yung Li of secretly filming him to steal Bitcoin from his hardware wallet, worth approximately $176 million. Audio recordings and search warrant evidence support the plaintiff's claims, and the court upheld the asset freeze order, but dismissed part of the claims. The judge believes the plaintiff has a very high chance of winning and recommends that the case be heard as soon as possible.

区块客14h ago

AI programming issues! The convenience store near-expiry product app "Food Hunter" has a major security problem, exposing home GPS data.

The recently launched "Food Saver Hunter" app has raised concerns due to security issues, with user GPS data leaking and questionable API authorization. Additionally, Amazon has encountered system failures and financial losses, highlighting the risks of over-reliance on AI for programming. Experts are calling for stronger human oversight to ensure safety and accuracy.

CryptoCity15h ago
Comment
0/400
No comments