Halfway through the run, come back to pay back the money, what happened to this DeFi?
Author | Qin Xiaofeng
Editor | Hao Fangzhou
Produced | Odaily

Author | Qin Xiaofeng
Editor | Hao Fangzhou
Produced | Odaily
image description(picture from CoinTelegraph)Recently, DeFi liquidity mining is hot, and various projects emerge in an endless stream, and various names such as vegetables, fruits, animals and plants are not enough. "Classical old leeks" also entered the venue one after another.
The editorial department of Odaily has also discussed how the DeFi craze will end in the end. One of them is that the code is not good enough to attract hackers, or the project party has left a back door, which will eventually lead to a sharp drop in currency prices.EMD, a DeFi mining project on EOS
In fact,He ran away and left a presumptuous declaration, but in the end the project party "admitted counsel" and returned some of the stolen assets.
Reminiscent of the return of funds by hackers in the DForce incident at the beginning of this year, and the recent return of assets by the founder of Sushiswap after cashing out, many people lamented:
This year's hackers and projects are not good, and they are not stubborn in running.
In fact,
(1) Event Review: IP Address Exposure Leads to Identity Leakage
On September 9, the SlowMist security team issued a reminder that EOS DeFi mining EMD (Emerald) was suspected of running away, and took away 780,000 USDT, 490,000 EOS, and 56,000 DFS.
The project party also arrogantly left a message to the victim: After the community vote, you have been frozen. EOS can do whatever it wants. Let's go back and do it, only by delivering food can we get happiness.
The unrepentant victims still leave a message to the hacker's address, hoping to return the stolen tokens. But no matter whether it is coercion or temptation, it is not easy to work, and the hackers who run away are always indifferent.
image description
(Victim's message)
At this time, the TokenPocket wallet stood up and said that it had mastered the IP address of the hacker. Since the running EMD project used TokenPocket wallet, it left information such as IP address and mobile device, and was located by TokenPocket. In addition, the victim began to call the police, and the police pursued, and the hackers panicked.
On the afternoon of September 11, the EMD project party stated in the transfer notes that they are willing to return the stolen assets, but (the community) must stop all (investigation) activities they are doing now, otherwise the private key will be destroyed. Subsequently, more than 260,000 EOS and 56,000 DFS were returned, but not all of the stolen assets were returned.
TokenPocket speculates that the gang has already divided the money, and some members of the team have returned the stolen assets, while others have not. Therefore, the victim has not yet solved the case, and the police are continuing to investigate; and, TokenPocket has negotiated with the police and submitted hacker-related materials. It is inconvenient to announce specific details.Chef Nomi It can be seen from the EMD incident that the project party was worried about legal sanctions due to the exposure of identity information, and eventually repaid the loan.
Coincidentally, on April 19 this year, dForce's decentralized lending protocol Lendf.Me was hacked, and encrypted digital assets worth about $25 million were stolen. After the case happened, the dForce team expressed their willingness to negotiate with the hackers, but they were ignored, and dForce reported the case to the Singapore police.
The case was finally resolved, again after the hacker leaked his IP address on the decentralized exchange 1inch. 1inch cooperated with the Singapore police and the dForce team to put pressure on the hackers to return the stolen money.
Also because he couldn't bear the pressure, he finally returned the ETH (worth 14 million US dollars) he had cashed out to the community.ForbesThe pressure on Chef Nomi mainly comes from two aspects:
One is that his true identity may be exposed. There was speculation that Chef Nomi might be Band co-founder Sorawit Suriyakarn, but the latter denied it; in addition, another Twitter user "0xMaki" suspected of being part of the SushiSwap team once posted that everything should be exposed, including Chef Nomi identity.
The second is pressure from the law. Due to Chef Nomi's cashing out, SUSHI fell sharply, investors suffered heavy losses and chose to defend their rights.
Forbes
According to the article, multiple SUSHI holders have launched a class action lawsuit against Chef Nomi. Although Chef Nomi has remained anonymous, with the involvement of the FBI and the IRS, Chef Nomi, who left his IP address on Twitter, is bound to escape.
To sum up, if it is not that there is no way out, and the fear of the real identity being exposed, these hackers and project parties who run away will not give any sympathy to the victims at all, and will not return their "achievements".
(2) Can hackers escape?
The above three cases actually all have one thing in common, that is, leaving IP or relevant evidence that can directly correspond to their entities.
Although the money was recovered, everyone should not take chances. Because these hackers are just beginners with no experience.
"He should be a good programmer, but he is an inexperienced hacker." 1inch founder Sergej Kunz said.
What would a top hacker do?
First of all, when a hacker visits a website (such as 1inch), he will not use our common browser that leaves an IP address. They will use proxy servers to satisfy their anonymity needs and avoid being tracked. The Onion Router (TOR for short) is the highest level of all tools and the most common choice.
After the theft is successful, hackers will not directly transfer the coins to large exchanges, because these exchanges have relatively complete anti-money laundering measures and have marked a large number of addresses, which are easy to trace to physical accounts.
One is to disperse the funds of the marked hacker account to multiple small accounts, transfer them multiple times, and finally gather them into small exchanges that do not require KYC certification for cash.
The second is to launder the stolen money through currency mixing platforms (such as swapcool). Such platforms not only support Tor access, but also promise users that there are no operation logs and no user transaction data will be recorded.
In the end, the stolen money was relaundered many times and flowed into the hacker's own account. Whether it is the police or a third-party company, it is difficult to trace.
According to data from SlowMist, over the past ten years, there have been 289 hacking incidents in the encryption market, causing a total loss of 13.0395 billion US dollars. But looking back at these attacks, there are very few crackers, which is why hackers have been rampant.
secondary title
(3) How to prevent it?







