1inch, the decentralized exchange (DEX) aggregator, faced a major security breach in its smart contracts last week. However, in a surprising turn of events, the exchange managed to recover most of the $5 million that was stolen after engaging in negotiations with the hacker.
The incident occurred on March 5 due to a vulnerability in an outdated version of the platform's smart contract. Following discussions and offering a substantial bug bounty, the hacker returned the majority of the stolen funds.
WuBlockchain reported that the hacker agreed to return most of the money taken from 1inch, while also receiving a portion as a bug bounty as per Decurity's postmortem report.
1inch identified the breach to be a result of a flaw in the Fusion v1 resolver smart contract, which was no longer up to date. The team discovered the attack around 6 PM UTC on March 5, as attackers exploited outdated logic within Fusion v1 to carry out unauthorized transactions.
Fortunately, no end users were directly impacted by the breach as it targeted a third-party market maker, TrustedVolumes. 1inch took swift action by redeploying its resolver contracts as a precaution to prevent further exploitation.
The hacker made an unexpected move by proposing a bug bounty in return for returning the stolen funds, leading to successful negotiations with TrustedVolumes, the affected market maker.
This unique resolution demonstrates a rare occurrence within the DeFi space where stolen assets were voluntarily returned, signaling a positive trend towards ethical hacking and constructive resolutions in the industry.
While this incident signifies the second security breach faced by 1inch in six months, it underscores the continuous security challenges that DeFi protocols encounter. Emphasizing the importance of ongoing monitoring and prompt response mechanisms to safeguard both users and assets.
Despite the recovery efforts, the 1INCH price has seen a modest increase of only 1.12% since Sunday, trading at $0.23 at the time of writing, underlining the need for regular smart contract audits and proactive vulnerability detection to prevent future incidents. Strengthening validation procedures is crucial to mitigate risks and ensure a secure DeFi environment.