Today’s Field Note
Two thefts today share a lesson: the smart contracts held. Ostium confirmed a $24 million exploit that it attributes to an off-chain breach, not a contract flaw, with trader collateral reportedly safe but liquidity providers awaiting a recovery plan. Separately, Seoul police detailed a ring that cloned Flare Network and its FXRP token, seeding Wikipedia entries, blog posts, and YouTube videos to lend the fake staking site credibility before draining $8.5 million in XRP. Both cases route around the code entirely, hitting operational keys, front ends, and human trust. When the audit report is clean and the money still leaves, the perimeter was never the contract.
Today’s Move
- If you are an Ostium LP, stop adding liquidity and wait for the published recovery plan before assuming your position is whole. Trader collateral is described as unaffected, but LPs are not.
- Verify any Flare or FXRP staking domain against the official Flare channels directly. Do not trust Wikipedia, blog, or YouTube links, which the XRP ring specifically weaponized.
- Revoke token approvals on any address you connected to an unfamiliar staking site recently, using Revoke.cash or Etherscan’s approval tool.
- Treat Ostium’s “off-chain breach” as a signal to rotate any operational or admin keys and audit front-end and infra access on your own protocol today.
- Bookmark and type exchange and staking URLs manually. The crypto.com phishing wave (refXXXXXX-crypto-app.com) is running the same playbook against retail.
Resources
- https://decrypt.co/374696/fake-flare-network-staking-site-drained-8-5m-in-xrp-seoul-police
- Incident trackers (reference standard): Rekt leaderboard · SlowMist Hacked
Related
- Token Approvals and the Infinite Allowance
- Multisig and Threshold Signing, Beyond Buying a Safe
- Browsers Assemble Their Own Malware While Bridges Bleed $31.7M
More: Issues · Field Notes · RTFM
Daily field notes, weekly Issues. Follow @ItsAlreadyPrice or subscribe via RSS.