Thunder Terminal Hack
What happened
On 27 December 2023 an attacker drained 114 user wallets on Thunder Terminal, a trading terminal for Ethereum and Solana, taking about 86.56 ETH and 439.12 SOL, roughly $240,000 at the time. The attack ran for about nine minutes, from 00:11 to 00:20 UTC, and ended when Thunder revoked all session tokens and transaction-signing access.
Thunder said the attacker got hold of a MongoDB connection URL from a third-party service and used it to pull user session tokens and execute withdrawals on users' behalf. The team said it does not store private keys, that desktop wallets were unaffected, and that the incident may be linked to the security breach MongoDB disclosed earlier that month. It promised full refunds to affected users.
The attacker disputed that account in an on-chain message, claimed to hold user data and demanded a 50 ETH ransom (about $110,000) not to leak it. ZachXBT traced the stolen funds to the Railgun privacy protocol.
How it happened
- The attacker obtained a MongoDB connection URL belonging to a third-party service Thunder used.
- Using that database access, they pulled active user session tokens.
- With the session tokens, they executed withdrawals on behalf of 114 users, moving ETH and SOL out of their wallets over about nine minutes.
- Thunder stopped the attack by revoking every session token and all transaction-signing access.
- The attacker moved the proceeds to Railgun and publicly demanded a ransom for the user data.
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis Thunder Terminal suffers hacker attack, losses amount to $240k crypto.news
- analysis What Happened In $240K Thunder Terminal Attack - Are Funds Safe? bitget.com
- analysis Cryptohack Roundup: Thunder Terminal Repels Attack govinfosecurity.com
- analysis jointherealworld.com page ai jointherealworld.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.