Invezz

ParaSwap confirms it is investigating possible private key exploit

ParaSwap confirms it is investigating possible private key exploit
Charles Thuo
Oct 11, 2022, 06:35 AM
  • ParaSwap was alerted of the likely private key exploit early today by blockchain security firm Supremacy Inc.
  • In particular, the exploit targeted the aggregator’s deployer address private key.
  • ParaSwap is currently investigating the issue.

ParaSwap, a decentralized exchange aggregator that provides the best prices over multiple DEXs on the Ethereum blockchain, has today confirmed it is investigating a possible private key hack. The exploit was brought to the attention of ParaSwap early today by Blockchain security firm Supremacy Inc. through a tweet thread.

The Supermacy warning read: “Your deployer address private key may have been compromised (possibly due to Profanity vulnerability). Funds have been stolen on multiple chains.”

ParaSwap investigating the issue

In a quick response to the posts by Supermacy ParaSwap team confirmed that it was looking into the issue saying:

Supermacy had included an Etherscan link to ParaSwap’s deployer contract address showing that someone accessed the aggregator’s private key and made several transactions on Fantom (FTM/USD), BNB Chain (BNB/USD), and Ethereum (ETH/USD). The transactions show that the hacker only transferred a few hundred dollars in each of the transactions.

While ParaSwap did not confirm the transaction, it did not deny any of the vulnerabilities as stated by Supermacy.

Later after confirming it was investigating the possible attack, ParaSwap in a follow-up tweet reported not finding any sign of an exploit on its deployer address. The tweet read: