Ethereum Layer 2 Rho Protocol Suffers $7.6M Security Breach

As a seasoned crypto investor with years of experience in this volatile market, I’ve seen my fair share of security breaches and hacks in the space. Each time, it feels like a punch to the gut, but I’ve learned to stay calm and assess the situation before reacting impulsively.


At RhoMarketsHQ, we’ve announced a security incident affecting our platform which operates on Ethereum Layer 2 solution, Scroll. The intrusion focused on our Oracle controls, resulting in a brief suspension of the platform’s services.

Rho Protocol Suffers $7.6M Security Breach

At RhoMarketsHQ, we’ve identified some questionable actions taking place on our platform, leading us to temporarily halt operations. The underlying issue was traced back to an intrusion caused by an unauthorized individual exploiting an Oracle control vulnerability.

Certain pools, including USDC and USDT, have been compromised, with the total stolen funds approximating $7.6 million across various blockchains. The affected party has given reassurances to users, stating that most pools remain secure and will be restored once the issue is resolved.

Scroll was notified of a potential exploit within our ecosystem.

As a diligent analyst, I’ve confirmed the information with RhoMarket’s team, and in response, Scroll has chosen to put on hold the completion of the chain to conduct a thorough examination of the current situation.

We have confirmed that the…

— Scroll (@Scroll_ZKP) July 19, 2024

Expert: At the Ethereum Layer 2 solution provider, Scroll, we confirmed an attack that occurred within the RhoMarkets ecosystem. After collaborating with the RhoMarkets team to authenticate the incident, Scroll initiated a response and delayed the chain’s finalization for thorough investigation. The findings indicate that this was an application-specific issue, and the finalization process can now proceed without delay. Per the report, RhoMarkets is proactively addressing the security breach.

Attacker’s Message and Intent

Expert: ZachXBT, a renowned blockchain investigator, disclosed that the hacker communicated with RhoMarkets via a cryptic on-chain message. The content of the message read:

“Hi RHO team, our MEV bot gained advantages from the price oracle issue in your system. We acknowledge that the affected funds belong to your users and we’re prepared to return them in full. However, before we proceed, we kindly request that you acknowledge this was not an exploit or hack but rather a misconfiguration on your part. Furthermore, could you please share your plans for preventing similar occurrences in the future?”

The attacker’s readiness to restore the funds becomes apparent if RhoMarkets acknowledges the misconfiguration. Regarding the security incident, Scroll urges its users to rescind all authorizations for their contracts with immediate effect.

This is Breaking Story Please Check Back for More

Read More

2024-07-19 16:56