Back to dashboard
Wednesday, July 19, 2017 at 15:00 UTC

Parity Multisig

Unprotected initWallet allowed ownership takeover.

Partial
Funds stolen
$30.00M
Recovered
$12.00M40%
Still outstanding
$18.00M
Chain
Ethereum
Category
Wallet
Attack vector
Access Control
Reported by
PeckShield
Incident ID
h2017-2

Exploit & recovery timeline

  1. Jul 19, 2017 · 13:00 UTC
    Attack preparation

    Attacker wallets funded and staged ahead of the access control exploit against Parity Multisig.

  2. Jul 19, 2017 · 15:00 UTC
    Exploit executed

    $30.0M drained from Parity Multisig on Ethereum via Access Control.

  3. Jul 19, 2017 · 16:00 UTC
    Detected by PeckShield

    PeckShield flagged the anomalous transactions and published an initial alert.

  4. Jul 19, 2017 · 19:00 UTC
    Protocol response

    Parity Multisig paused affected contracts or withdrawals and began tracing outbound flows.

  5. Jul 20, 2017 · 15:00 UTC
    Funds traced

    Stolen assets followed through mixers, bridges, and exchange deposit addresses.

  6. Jul 26, 2017 · 15:00 UTC
    Partial recovery

    $12.0M of $30.0M recovered (40%); the remainder is still unaccounted for.

  7. Aug 18, 2017 · 15:00 UTC
    Investigation continues

    Remaining funds monitored across chains with exchange partners notified.