Foom.Cash loses $2.26 million due to zkSNARK vulnerability

ETH-2.89%

Foom.Cash security protocol, built on Ethereum, was recently exploited due to a cryptographic verification vulnerability, causing estimated damages of $2.26 million. The attack affected contracts on both Ethereum and Base, resulting in the loss of over 24.28 trillion FOOM tokens. A transaction on Base caused a loss of approximately $427,000, while transactions on Ethereum worth $1.83 million are believed to be “white-hat” efforts to recover assets.

According to GoPlus Security, misconfigured verification keys allowed attackers to impersonate zkSNARK proofs. Certik and BlockSec described this as a “copycat” attack similar to the previous Veil Cash incident. Although promoted as an upgrade of Tornado Cash, Foom.Cash has not issued an official response or remediation plan.

View Original
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Axiom Employee Allegedly Exploits Dashboard for Insider Trading

Allegations against Axiom Exchange reveal that Broox Bauer exploited internal dashboards to track private wallets for insider trading schemes, targeting high-volume traders. The lack of access controls raises significant security concerns, prompting calls for investigation.

CryptoFrontNews45m ago

AI Cryptocurrency Scams Surge 500%! Generative Artificial Intelligence Becomes a New Weapon for Hackers, Single-Transaction Profits Increase 4.5 Times

TRM Labs reports that AI cryptocurrency scam activities have surged by approximately 500% over the past year. Hackers are using AI to generate phishing emails and fake websites, with deepfake technology accelerating emotional scams. The scale of illegal crypto transactions is expected to reach $158 billion in 2025, highlighting the urgent need to upgrade security defenses.

GateNews48m ago

XRP Ledger Foundation confirms fixing a serious vulnerability in an unreleased revision

The XRP Ledger Foundation has confirmed the fix of a serious vulnerability present in Ripple's signature verification logic, which could allow attackers to steal funds. The patch has not yet been activated on the mainnet, and validators are currently advised to vote against it. An emergency release was issued on February 23 to prevent exploitation of the vulnerability.

TechubNews3h ago

South Korean police have arrested two suspects in the $1.4 million Bitcoin theft case

South Korean police have arrested two suspects in connection with a 22 Bitcoin theft case worth approximately $1.4 million. These Bitcoins were originally seized by the police during a hacking attack but were stolen due to improper storage, with the mnemonic phrase handed over to "Mr. Jeong," who is involved in a loan agreement. The case was uncovered during an audit.

GateNews3h ago

Holdstation suffered a hacking attack resulting in a loss of 462,000 USDT, has suspended services, and promises full compensation.

Holdstation suffers a supply chain attack, with attackers stealing developer session tokens and injecting malicious code, resulting in a loss of 462,000 USDT funds. The team has suspended services, pledged to compensate affected users, and is working with security teams to investigate.

GateNews3h ago

User wallet information exposed! On-chain detective ZachXBT reveals Axiom employee suspected of insider trading

Well-known on-chain detective ZachXBT revealed that Axiom employees at the crypto trading platform abused internal tools to spy on users' wallets and may have used this information for insider trading. Axiom has revoked the relevant access rights and stated that an investigation into the misconduct is underway, emphasizing that this does not represent the overall team values. The investigation has sparked heated discussion in the market, and some traders have profited from predicting the event.

区块客3h ago
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)