Luke Dashjr Hack
Incident Overview
Luke Dashjr's PGP key was compromised, leading to losses worth 3.6M USD.
Luke Dashjr's bitcoin cold wallet was compromised. Potentially it could be malware inside some downloaded app like Bitcoin Knots or Core. The hacker's profit is about 216.93 BTC or $3.6M USD.
Some of the bitcoin transfers tx:
https://www.blockchain.com/explorer/transactions/btc/432ded946431a9612f09d73bd15ded045d11d1095ffdfe8d68306ea9b2e78930
https://www.blockchain.com/explorer/transactions/btc/c38a3210fbb758cfc41d9a64b7534b83aecca96f051231f15545e8e5c7365190
https://www.blockchain.com/explorer/transactions/btc/4b3cde50e2bce3d02e15b61957d2452e29f53d9a99e1ab14e83b6ec0f87fd851
https://www.blockchain.com/explorer/transactions/btc/50df1eab0bf2bd01999cea4fc531a65c17e1a285823c9ae4eab0feb7e21a11b6
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Luke Dashjr, these are the critical security checks that could have prevented this incident (December 2022).
- Verify all logic paths related to Access Control are guarded by proper access controls and input validation - see the Access Control Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
Learn to Prevent the Next Luke Dashjr
The Luke Dashjr hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.