|

Ethereum’s layer 2 solution Optimism crashes following 20 million OP tokens hack

  • Wintermute discovered that it could not access the tokens due to technical oversight and an attacker took control of the contract on L2, retrieving the 20 million OP tokens. 
  • Optimism price posted double-digit losses since the hack. 
  • The attackers have cashed out 1 million OP tokens through Tornado Cash; it is not a white hat exploit. 

Optimism price took a hit after a hacker stole 20 million of its tokens whilst in transit to market maker Wintermute. The attack was thought to have resulted from a technical oversight by the market maker. Optimism, which is transparent in its updates, informed the community that  it had now reimbursed Wintermute with an additional 20 million replacement tokens post the attack. 

Also read: Everything you need to know about Ethereum's Merge testnet upgrade

Optimism tokens lost to attack on market maker Wintermute

Optimism, a low-cost lightning-fast Ethereum layer-2 blockchain, informed the community of the loss of 20 million OP tokens from a malicious attack. Optimism engaged market maker Wintermute to provide liquidity for its tokens, sending them 20 million OP. 

Due to a technical oversight, Wintermute discovered they could not gain control of the OP tokens since the smart contract was still on L1 and had not been updated to be deployed on Optimism. This technical oversight left Wintermute vulnerable to a hack, and a bad actor took charge of the situation, grabbing 20 million OP tokens on the L2 for themself. 

One million out of the 20 was moved to Tornado Cash, enabling users to send and receive funds from a mixed source. The attacker converted OP to Ethereum and sent it to an unknown address via Tornado Cash. 

Another 1 million has been withdrawn over the past hour, and the wallet’s balance is now 18 million OP tokens. 

Attacker's wallet with a balance of 18 million OP tokens

Attacker’s wallet with a balance of 18 million OP tokens

As soon as Wintermute became aware of the attack, it began a recovery operation with the goal of deploying the L1 multisig contract to the same address on L2. The remedy arrived too late, and the attacker had already taken control of the 20 million OP tokens, cashing out 2 million in the process. 

Optimism’s transparency update arrived late

While the team at Wintermute informed Optimism Foundation of the attack on May 30, 2022, the layer-2 solution chose to wait to publish a transparency update on June 9, 2022. 

The initial deployment of 20 million tokens occurred two weeks ago. After learning about the attack, Optimism provided another 20 million tokens to Wintermute while the market maker worked to retrieve the lost tokens. 

Wintermute was under the impression that the funds were recoverable only by their team; however, this assumption was proven false when the attacker started selling their OP token holdings, by converting them to Ethereum and then transferring them to unknown addresses on Tornado Cash. 

Wintermute consulted with the Gnosis Safe team, asking them for their assessment and help in attempting to recover the lost OP tokens. 

Kelvin Fichter, a researcher and developer, shared detailed insights into the incident in a Twitter thread, revealing key details of the attack and how it could have been prevented

How the attacker stole 20 million OP tokens

In less than 24 hours of Wintermute notifying Safe and Optimism, wallet 0x8BcFe4f1358E50A1db10025D731C8b3b17f04DBB was funded via tornado cash transfer 134. 

The attacker replayed the Gnosis Safe MasterCopy 1.1.1 deployment from the Ethereum mainnet and used the previously deployed contract 

0xE7145dd6287AE53326347f3A6694fCf2954bcD8A to deploy vaults per batches of 162. The hacker then proceeded with selling 1 million OP tokens for ETH and withdrew back to L1 via Synapse and Hop bridges to then use tornado cash on the mainnet.

What Wintermute is doing

According to their confessional transparency update, the initial error in which Wintermute was unable to access OP tokens was 100% their fault. Wintermute, a market maker with a global reach, is now intent on buying OP every time the attacker sells to make the protocol whole eventually. 

After the attacker’s 1 million OP tokens sale, Wintermute purchased an equivalent amount, and the market maker believes this is not a white hat exploit. Wintermute acknowledges that the attacker’s sale of OP tokens can potentially create price volatility in OP tokens. 

Since the announcement, OP token price has plummeted by 14%. 

Wintermute left a message for the attacker, however there is no update on any response. 

Crypto Twitter criticizes Optimism and Wintermute

Dovey Wan, advisor to Coindesk, criticized Wintermute for making an amateur mistake. Deploying the multisig contract on the wrong chain is an “amateur mistake,” Wan told Twitter followers. 

Dovey believes the Optimism team should have postponed the airdrop for a better consequence and pushed out the transparency report to later. 

Author

Ekta Mourya

Ekta Mourya

FXStreet

Ekta Mourya has extensive experience in fundamental and on-chain analysis, particularly focused on impact of macroeconomics and central bank policies on cryptocurrencies.

More from Ekta Mourya
Share:

Editor's Picks

Ripple remains under pressure as licensing operations expand across Europe

XRP lags behind other crypto majors, declining for the second consecutive day on Thursday. Ripple secures preliminary approval for an Electronic Money Institution license from the CSSF, Luxembourg's financial regulator.

Crypto Today: Bitcoin, Ethereum, XRP rally stalls despite ETF inflows boosting investor optimism

Bitcoin holds above the 100-day EMA after correcting from the previous day’s high amid surging ETF inflows. Ethereum posts a minor correction on Thursday after a notable bullish move above $3,400, reflecting potential profit-taking.

Bitcoin steadies above $96,000 as ETF inflow surges, derivatives suggest further rally

Bitcoin price holds above $96,000 on Thursday after hitting a nearly two-month high at $97,800 the previous day. The bullish price action in BTC is further supported by rising institutional demand, as evidenced by three consecutive days of inflows into spot ETFs this week. 

Monero risks deeper correction as rally fatigues at $800 record high

Monero (XMR) edges lower on Thursday, holding around $700 at the time of writing as the rally cools off after reaching a record high of $800 on the previous day, signaling a potential cycle top. 

Orange Juice Newsletter – Smart insights by real people. Every day.

A free newsletter highlighting key market trends to help traders stay a step ahead. Daily insights on the most relevant trading topics, compiled by our experts in an easy-to-read format so you never miss an important move.

Bitcoin: Early-2026 rally falters as BTC investors await key catalyst

Bitcoin (BTC) is trading lower toward $90,000 on Friday after encountering rejection at a key resistance zone. The price pullback in BTC is supported by fading institutional demand, as spot Exchange Traded Funds (ETFs) have recorded net outflows so far this week.