{"id":19963,"date":"2025-04-01T03:16:32","date_gmt":"2025-04-01T03:16:32","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=19963"},"modified":"2025-04-01T03:16:32","modified_gmt":"2025-04-01T03:16:32","slug":"sir-trading-begs-hacker-to-return-255k-or-no-chance-for-us-to-survive","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=19963","title":{"rendered":"SIR.trading begs hacker to return $255K or \u2018no chance for us to survive\u2019"},"content":{"rendered":"<div>\n<p style=\"float:right; margin:0 0 10px 15px; width:240px;\"><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjUtMDQvMDE5NWVlZDQtNDdmYS03Nzk3LTgzYTktODk2N2QwMzhjN2Nk.jpg\"><\/p>\n<\/p>\n<p style=\"float:right; margin:0 0 10px 15px; width:240px;\"><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjUtMDQvMDE5NWVlZDQtNDdmYS03Nzk3LTgzYTktODk2N2QwMzhjN2Nk.jpg\" alt=\"SIR.trading begs hacker to return $255K or \u2018no chance for us to survive\u2019\"><\/p>\n<p>The founder of the recently hacked decentralized finance protocol SIR.trading has made an emotional plea to the attacker, asking them to return around 70% of the stolen customer funds otherwise, the protocol will not survive.<\/p>\n<p>\u201cHere is my proposal, keep $100k as a fair share for your critical bug find, and return the remaining,\u201d SIR.trading\u2019s pseudonymous founder \u201cXatarrer\u201d <a data-ct-non-breakable=\"null\" href=\"https:\/\/etherscan.io\/idm?addresses=0x5000ff6cc1864690d947b864b9fb0d603e8d1f1a,0x27defcfa6498f957918f407ed8a58eba2884768c&amp;type=1\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">wrote<\/a> in a March 31 onchain message to the attacker following the <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/defi-protocol-sir-trading-loses-entire-355-k-tvl-exploit\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">$355,000 hack on March 30.<\/a><\/p>\n<p>\u201cWe\u2019ll call it even. No legal games, no drama,\u201d they added.\u00a0<\/p>\n<p>Xatarrer said that SIR.trading was built on the back of four years of late-night coding and $70,000 from friends and believers without any additional venture capital funding.<\/p>\n<blockquote><p>\u201cWe grew to $400k TVL organically without any advertising. If you keep 100% of the funds, there is no chance for us to survive.\u201d<\/p><\/blockquote>\n<p>Xatarrer even praised <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/north-korean-crypto-attacks-rising-sophistication-actors-paradigm\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">the hacker for the sophisticated hack,<\/a> stating that it was \u201calmost beautiful if it wasn\u2019t for all the funds people lost.\u201d<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2025-04\/0195ef27-5b66-7e12-baf2-01b2a3fcf874\" title=\"\" alt=\"SIR.trading begs hacker to return $255K or \u2018no chance for us to survive\u2019\"><figcaption style=\"text-align: center;\">\n<p><em>Source: <\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/leveragesir\/status\/1906700496607248812\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\"><em>SIR.trading<\/em><\/a><\/p>\n<\/figcaption><\/figure>\n<p>The hacker hasn\u2019t responded and has already transferred the stolen funds through to Ethereum privacy solution Railgun, <a data-ct-non-breakable=\"null\" href=\"https:\/\/etherscan.io\/address\/0x27defcfa6498f957918f407ed8a58eba2884768c#tokentxns\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">according<\/a> to data from Ethereum block explorer Etherscan.<\/p>\n<p>Xatarrer initially said on March 30 that the SIR.trading team intended to keep the protocol up and running despite the setback. \u201cWe\u2019ve already started planning our next steps. Those impacted by the hack will not be forgotten,\u201d it <a data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/leveragesir\/status\/1906826367540310232\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">said<\/a> on March 31.<\/p>\n<h2><strong>Hack resulted from feature added to Ethereum\u2019s Dencun upgrade<\/strong><\/h2>\n<p>The hacker targeted a callback function used in the protocol\u2019s \u201cvulnerable contract Vault\u201d which leverages Ethereum\u2019s transient storage feature.\u00a0<\/p>\n<p>The hacker managed to replace the real <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/explained\/fake-crypto-liquidity-pools-how-to-spot-and-avoid-them\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">Uniswap pool address<\/a> used in this <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/explained\/reentrancy-attacks-in-smart-contracts-explained\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">callback function<\/a> with an address under the hacker\u2019s control, allowing them to redirect the funds in the vault to their address by repeatedly calling the callback function until all of the protocol\u2019s total value locked was drained.<\/p>\n<p>The transient storage feature was <a data-ct-non-breakable=\"null\" href=\"https:\/\/eips.ethereum.org\/EIPS\/eip-1153\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">added<\/a> to Ethereum in the March 2024 <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/dencun-upgrade-live-ethereum-mainnet\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">Dencun upgrade<\/a> as a solution to offer users lower gas fees than gas typically required for regular storage.<\/p>\n<p><em><strong>Related:<\/strong><\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/defi-security-improvements-vs-cefi-losses-2024\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\"><em><strong> DeFi hacks drop 40% in 2024, CeFi breaches surge to $694M \u2014 Hacken<\/strong><\/em><\/a><\/p>\n<p>SIR.trading\u2019s <a data-ct-non-breakable=\"null\" href=\"https:\/\/docs.sir.trading\/\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">documentation<\/a> shows that it was billed as \u201ca new DeFi protocol for safer leverage\u201d to address some of the challenges that often occur in leveraged trading \u2014 such as volatility decay and liquidation risks.<\/p>\n<p>It comes as crypto lost to exploits and scams fell to $28.8M in March, blockchain security firm CertiK <a data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/CertiKAlert\/status\/1906677902642450630\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">said<\/a> in a March 31 X post. Around $4.8 million was subtracted from that figure after hackers involved in the <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/1inch-loses-5m-hack-fusion-v1-smart-contract\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">1inch Resolver incident<\/a> returned the stolen funds.<\/p>\n<p>Crypto exploits and scams had one of its worst months in February, headlined by the <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/bybit-hacker-launders-1-billion-stolen-funds\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\">$1.4 billion Bybit hack.<\/a><\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/magazine\/ethics-101-crypto-projects-negotiate-hackers\/\" rel=\"null\" target=\"null\" text=\"null\" title=\"null\"><em><strong>Should crypto projects ever negotiate with hackers? Probably<\/strong><\/em><\/a><\/p>\n<p><template data-name=\"subscription_form\" data-type=\"defi_newsletter\" label=\"Subscription Form: DeFi Newsletter\"><\/template>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The founder of the recently hacked decentralized finance protocol SIR.trading has made an emotional plea to the attacker, asking them to return around 70% of the stolen customer funds otherwise, the protocol will not survive. \u201cHere is my proposal, keep $100k as a fair share for your critical bug find, and return the remaining,\u201d SIR.trading\u2019s [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-19963","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/19963","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19963"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/19963\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19963"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19963"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19963"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}