









The Dolomite Exchange suffered an exploit of its old contracts on Ethereum, resulting in a loss of approximately $1.8 million in USDC. The attackers utilized a loophole in the TradeManager contract, bypassing reentrancy guards and exploiting the batchTransfer function of the TradeDelegate contract. This allowed them to transfer tokens approved to the contract from users, leading to a loss of ~$1.9m. In response, Dolomite confirmed that the hack did not impact their current product on the Arbitrum chain. Additionally, the AirDAO team reported a theft from their AMB/ETH Uniswap pool, losing 35.2 million AMB tokens and 125.51 ETH (totaling approximately $880K) due to a social engineering scam. Efforts are underway to identify the hacker and retrieve the stolen funds. Meanwhile, a wallet associated with BlackRock's new institutional crypto fund received 0.97 unsolicited ETH via Tornado Cash, potentially creating legal issues. This incident underscores the vulnerabilities and regulatory challenges within the cryptocurrency ecosystem.
1/ A wallet associated with BlackRock’s onchain BUIDL fund was dusted with 0.97 ETH that had passed through Tornado Cash, a U.S. government sanctioned entity. Dust attacks involve sending unsolicited tokens for the purpose of scamming, doxxing, or simply memeing. https://t.co/p6aBjXnWI6
📥 A wallet associated with Blackrock’s fund received Tornado Cash-dusted ETH. 💫 @carlosdomingo has a suggestion for an Ethereum Improvement Proposal that could prevent these situations for other institutions wanting to use Ethereum. Listen now: https://t.co/l9MC2actY5 https://t.co/fE7FYqd7eb
AirDAO exploited via social engineering attack March 20, 2024 https://t.co/SpUsMzvhY0 https://t.co/Tb8mvYxMFN