Refreshed 22m ago· updates every 6h

Qubit Finance (2022) — Crypto Hack

Laundered
Jan 27, 2022·
BSCEthereum
Amount Stolen
$80.0M
206,809 BNB
Recovered
$0

Qubit's QBridge exploit allowed minting of unlimited xETH collateral by depositing zero ETH on Ethereum via a logic error.

Summary

Qubit's QBridge exploit allowed minting of unlimited xETH collateral by depositing zero ETH on Ethereum via a logic error.

How It Was Compromised — Bridge via Smart Contract Exploit

BridgeSmart Contract Exploit

Qubit Finance's QBridge contract contained a critical vulnerability allowing attackers to call the deposit() function with zero ETH and still receive xETH tokens on BSC as collateral. The attacker then used this collateral to borrow all available assets from QBridge's liquidity pools. The bug stemmed from failing to check for zero-value deposits.

Fund Flow & Laundering Analysis

206,809 BNB quickly dispersed across multiple BSC wallets. Qubit team published an on-chain message requesting fund return with a $250K bounty offer. Attackers never responded. Funds subsequently routed through cross-chain bridges and exchanged for stablecoins on multiple DEXes.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.