Fireblocks Hack
Incident Overview
Fireblocks company lost 75,000,000 $USD due to the negligence of the security engineer
FireBlocks is an Israeli company that offers traditional financial institutes a seamless plug into the decentralized finance ecosystem and its customers. Cryptocurrency company StakeHound has filed a lawsuit against Fireblocks, claiming that it lost NIS 245.5 million (approximately $75 million) worth of cryptocurrencies it was entrusted with. StakeHound claims that Fireblocks, a developer of secure cross-enterprise asset transfer infrastructure, was negligent and as a result, the funds have been lost and can not be recovered.
Fireblocks has denied any wrongdoing, claiming that: "The keys were generated by the client and stored outside the Fireblocks platform," and that "the customer did not store the backup with a third-party service provider per our guidelines."
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Fireblocks, these are the critical security checks that could have prevented this incident (June 2021).
- Verify all logic paths related to Access Control are guarded by proper access controls and input validation - see the Access Control Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
-
01
Source 1 https://archive.is/wgthY
-
02
Source 2 https://archive.is/zefFz
Learn to Prevent the Next Fireblocks
The Fireblocks hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.