According to the latest reports, Bitcoin DeFi platform ALEX Lab recently suffered a major security incident. As of 11:00 am on June 17, 2024, the attacker had broadcast more than 9,700 transactions involving the generation of new wallet addresses and the dispersion of the on-chain STX balances to these new wallets. This action caused the number of traceable transactions to increase rapidly from 300 to more than 9,600, and the growth rate showed no signs of slowing down. This means that the number of independent addresses of the attacker increased from less than 100 to more than 4,700 in 7 days.
In this attack, a small amount of STX was transferred to thousands of new addresses and then sent to CEX (centralized exchanges). Most CEXs fully cooperated with ALEX Lab in the recovery process. However, the attacker soon realized this and quickly turned to the sending address of the stolen funds in CEX. Currently, the amount of traceable STX deposited into CEX is 8,373,587
#stx被盗 , while the attacker's current on-chain balance is about 5,560,332
$STX (calculated based on wallet balances of more than 100 STX).
In addition, ALEX Lab has recovered some of the stolen funds and is considering remediation measures for affected users. The attacker initially took over the administrator privileges of a vault associated with the ALEX liquidity pool, affecting all assets in it, including approximately 13.7 million STX. About 3 million of them were sent to various CEXs, and this amount is still increasing. The balance is retained in several wallets. So far, the team has recovered all aBTC, sUSDT, xBTC, xUSD, ALEX, atALEX, LiSTX, LUNR, SKO, CHAX, $B20, ORDG, ORMM, ORNJ, TRIO, TX20, and STXS. ALEX's smart contract code and infrastructure have not been compromised.
To further recover the stolen funds, the team is sharing current forensic data with all relevant CEXs and preparing to file a police report. If the attacker does not cooperate in a timely manner, the team will obtain police support to assist in fund recovery efforts. At the same time, officials are also evaluating the use of ALEX reserves held by the Alex Lab Foundation to fund a treasury grant program to support communities affected by the attack.