VeChain Hack
What happened
At 12:27 UTC on 13 December 2019, about 1.1 billion VET, worth about $6.5 million, was taken from the VeChain Foundation's buyback wallet and sent to 0xD802A148f38aBa4759879c33E8d04deb00cFB92b. The blockchain itself was not hacked. According to the Foundation, a member of its finance team had not followed the approved standard procedure. They created the buyback wallet on a personal computer, and the private key was stolen during that temporary setup step. The Foundation said the VeChainThor mainnet and its official wallet software were not affected.
The Foundation asked exchanges to blacklist and freeze funds from the thief's addresses. VeChainStats published a live blacklist, and Hacken's whitehat network helped trace the funds. The thief split the funds across thousands of new wallets and launched DDoS attacks on the VeChainStats blacklist. On 18 December the Steering Committee released VeChainThor v1.1.5, which let Authority Masternodes block the thief's addresses. By 22 December, 469 addresses holding about 727 million VET were frozen, and the Foundation proposed an all-stakeholder vote on making the block permanent, which would in effect burn those tokens. CFO Jay Zhang stepped down, and he and CEO Sunny Lu each gave up 50% of their 2020 pay. The case was reported to Singapore police.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.