HTX hacker returned the money! Respond with strange English, take the bug bounty obediently
In late September, the HTX exchange was hacked for 4,999 ETH. Justin Sun stated that he accepted the "small loss" of nearly 8 million Euros and was willing to fully compensate. As of October 7th, data analysis account Lookonchain observed that the hacker had returned the 4,999 ETH and was even willing to claim the bug bounty.
HTX Global Hacker just returned the stolen funds of 4,999 $ETH ($8.2M). @justinsuntronhttps://t.co/fIxrm01a4zhttps://t.co/gHM0Yjqlqs pic.twitter.com/zX1mdDsRpi
— Lookonchain (@lookonchain) October 7, 2023
Table of Contents
Hacker Leaves Response in Broken English, Returns Bug Bounty
The hacker incident was suspicious from the start, with HTX receiving early warnings but not disclosing the information to users immediately. They only communicated with the hacker through blockchain messages, offering to fully compensate for the losses.
At the time, HTX left a message: "We have confirmed your real identity. Please return the funds to 0x18709E89BD403F470088aBDAcEbE86CC60dda12e. We will provide you with a 5% white hat bonus. This offer is valid for 7 days, until October 2, 2023. If you do not return the funds by the deadline, we will seek legal intervention." Blockchain message
After the deadline set by HTX passed, HTX did not announce any information regarding legal intervention; however, the hacker returned the money voluntarily, without even claiming the 5% white hat bonus.
The hacker left a strange English message for the bounty: "Received your message. white hat bonus to 0x1Fc8674A51D6b97C968BE384337519CE7003152B. your system hot wallet private key leak, you should change system hot wallet address and reduce the system hot wallet rate."
In this message, phrases like "your system hot wallet private key leak," "system hot wallet address," and "system hot wallet rate" are strung together with multiple nouns, lacking natural articles to convey the meaning, showing unnatural English usage. It is unclear if this was intentional obfuscation or the work of a non-native English speaker.
HTX Awards $410,000 Bounty
HTX gave the hacker 250 ETH and informed them that they made the right decision, providing an email address for the hacker to submit a vulnerability analysis report to help prevent similar incidents from occurring.
Update: HTX/Huobi just sent them a whitehat bounty of 250 ETH ($410K) along with this message
0x481cc79ee51b417ecfbdcfaa21cefd5b91bc8c2bc6d98a7065a3fb47e5849db3 pic.twitter.com/TeddYYukuH
— ZachXBT (@zachxbt) October 7, 2023
Related
- Beware of Dogecoin Scams! Stolen before doubling, cybersecurity experts warn of security issues on Dogecoin websites
- Suspected Official Hack? Well-known game L3E7 faces cybersecurity concerns, downloading the game leads to adult websites.
- Meta blocks WhatsApp accounts: Iranian hacker group attempts to steal US election data