NoOnes CEO Ray Youssef discloses $8 million exploit weeks after the fact, confirming crypto sleuth ZachXBT's investigation

CN
Theblock
Follow
1 day ago

Peer-to-peer crypto trading platform NoOnes has confirmed it suffered a security breach earlier this month leading to the loss of approximately $8 million in crypto assets, according to a post from CEO Ray Youssef. The disclosure came shortly after crypto sleuth ZachXBT posted it in his “Investigations by Zach” Telegram channel.

Youssef, the former CEO of rival P2P platform Paxful, said the losses were due to an “exploit of our Solana bridge” on Jan. 1. The company took steps to disable the security bridge, which remains offline, according to its status page.

“Our security teams quickly responded and the situation was immediately contained,” Youssef posted on X on Friday. “User funds SAFU [secure asset fund for users] and personal data SAFU. We know Solana is hot now but Solana will not come back up until exhaustive pen testing is done.. Apologize for the inconvenience.”

According to ZachXBT, NoOnes lost approximately $7.9 million on the Ethereum, Tron, Solana and Binance Smart Chain networks. Over the course of two days, the platform's hot wallets were slowly drained through “hundreds of suspicious outflows,” typically totaling about $7,000 per transaction. These funds were then mixed using Tornado Cash.

“Shortly after the platform made an announcement about maintenance although no official statement was made about any security incident,” ZachXBT said in his writeup of the attack. 

Funds were bridged to Ethereum/BSC and then deposited to Tornado Cash. 

The NoOnes’ status page also notes that its connectivity to the TON blockchain is affected in addition to Solana. SOL deposits are currently suspended. The page does not list a Solana wallet. 

NoOnes, which is primarily focused on markets in the developing world, has seen $2.7 million in trading volume in the past 24 hours, with BTC accounting for 76% of those trades and USDT for the remainder. Apparently, no ETH, USDT or monero has been exchanged on the platform, according to its “CEO Dashboard.”

Youssef’s previous company, Paxful, was temporarily shut down in 2023 amid “irreconcilable differences” of opinion between its co-founders that led to an exodus of key staff. Youssef closed the exchange and expressed concerns about the safety of customer funds after his co-founder Artur Schaback sued Youssef and the company for wrongful termination. 

Paxful, founded in 2015, reopened about a month later. Time Magazine listed it as one of the most influential companies of 2022 after garnering 9 million users and volumes of $5 billion. Youssef also co-founded the humanitarian organization Built with Bitcoin, which runs educational programs about financial literacy (i.e., using bitcoin) across Africa.

Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2024 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink