Thunder Terminal Hack

Reported loss $240K
Ethereum Solana
Key Leaked via Infrastructure

What happened

On 27 December 2023 an attacker drained 114 user wallets on Thunder Terminal, a trading terminal for Ethereum and Solana, taking about 86.56 ETH and 439.12 SOL, roughly $240,000 at the time. The attack ran for about nine minutes, from 00:11 to 00:20 UTC, and ended when Thunder revoked all session tokens and transaction-signing access.

Thunder said the attacker got hold of a MongoDB connection URL from a third-party service and used it to pull user session tokens and execute withdrawals on users' behalf. The team said it does not store private keys, that desktop wallets were unaffected, and that the incident may be linked to the security breach MongoDB disclosed earlier that month. It promised full refunds to affected users.

The attacker disputed that account in an on-chain message, claimed to hold user data and demanded a 50 ETH ransom (about $110,000) not to leak it. ZachXBT traced the stolen funds to the Railgun privacy protocol.

How it happened

  1. The attacker obtained a MongoDB connection URL belonging to a third-party service Thunder used.
  2. Using that database access, they pulled active user session tokens.
  3. With the session tokens, they executed withdrawals on behalf of 114 users, moving ETH and SOL out of their wallets over about nine minutes.
  4. Thunder stopped the attack by revoking every session token and all transaction-signing access.
  5. The attacker moved the proceeds to Railgun and publicly demanded a ransom for the user data.

Protocol details

Classification Frontend & Infrastructure
Protocol Type CEX
Protocol links Website @tate_terminal

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.