Menu
Browse

Cyber Incident Victim: Qubit Finance

Date:

Jan 2022

Location:

United States of America

Summary

A decentralized finance platform suffered an $80 million cryptocurrency theft due to an exploit in its Ethereum blockchain contract, allowing the attacker to steal Binance coins. The platform publicly acknowledged the breach and attempted to negotiate with the hacker by offering a bug bounty reward for the return of funds, though no communication confirmation was provided. This incident underscores recurring security vulnerabilities in cross-chain bridge protocols within the DeFi ecosystem.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On January 27, 2022, Qubit Finance, a decentralized finance platform enabling cryptocurrency loans and speculation, suffered an exploit resulting in the theft of approximately $80 million worth of cryptocurrency. The attack occurred late that evening, with the platform formally acknowledging the incident within hours. According to Qubit’s incident report, the threat actor stole 206,809 Binance coins (BNB) from the platform’s wallet by exploiting a vulnerability in one of its Ethereum blockchain contracts. This contract was integral to processing user transactions. Blockchain analysis confirmed the attacker’s address, and at the time of reporting, the stolen funds remained in the attacker’s possession without evidence of laundering attempts.

Cyber Incident Image

Qubit initiated recovery efforts by sending the attacker a private message through a blockchain transaction’s "private note" feature, offering a bug bounty reward in exchange for returning the stolen assets. The platform reinforced this appeal with a public message on its Twitter account, urging the hacker to disclose the vulnerability and negotiate a bounty. The company did not confirm whether the attacker responded to these communications. If unrecovered, the theft would rank among the Top 10 largest decentralized finance platform hacks recorded. Industry experts, including ZenGo CTO Tal Be’ery, contextualized the incident as part of a broader pattern of exploits targeting bridge projects, which face heightened risks due to their token exchange mechanisms. The hack disrupted Qubit’s operations and underscored systemic security challenges in DeFi infrastructure.

Sources
Sources available to members
2 sources