OKEx Hack
What happened
In the first of several 51% attacks on Ethereum Classic in August 2020, an attacker double-spent 807,260 ETC (about $5.6 million) against the OKEx exchange. The attacker rented hash power, mined a hidden version of the chain and then released it, so the ETC deposit OKEx had credited disappeared from the chain's history after the attacker had already traded it and withdrawn the proceeds. Bitquery traced the reorganization, which replaced blocks mined over several days, and estimated the rented hash power cost about 17.5 BTC (about $192,000).
OKEx published its account of the attack in mid-August 2020. It blacklisted the attacker's addresses, suspended the five accounts involved, paused ETC deposits and withdrawals, and planned longer ETC confirmation times. It considered delisting ETC but chose not to rush that decision.
How it happened
- From 26 June 2020 the attacker registered five OKEx accounts, all of which passed level 2-3 identity checks.
- On 30-31 July the accounts deposited about 68,230 ZEC and traded it for 807,260 ETC, which was withdrawn to the attacker's own addresses.
- Using hash power rented through NiceHash, the attacker privately mined an alternative ETC chain in which the 807,260 ETC went from one attacker wallet to another and never reached OKEx.
- On the public chain the attacker deposited the 807,260 ETC back into OKEx, traded it for about 78,941 ZEC and withdrew the ZEC at once.
- The attacker then published the longer hidden chain. The network reorganized onto it, erasing the ETC deposit OKEx had credited, while the ZEC withdrawal on the Zcash chain stood.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.