• bitcoinBitcoin (BTC) $ 90,343.00
  • ethereumEthereum (ETH) $ 3,095.26
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.03
  • bnbBNB (BNB) $ 886.27
  • usd-coinUSDC (USDC) $ 0.999958
  • solanaWrapped SOL (SOL) $ 133.08
  • staked-etherLido Staked Ether (STETH) $ 3,095.09
  • tronTRON (TRX) $ 0.273230
  • dogecoinDogecoin (DOGE) $ 0.137833
  • cardanoCardano (ADA) $ 0.410496
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • whitebitWhiteBIT Coin (WBT) $ 60.55
  • wrapped-stethWrapped stETH (WSTETH) $ 3,781.51
  • bitcoin-cashBitcoin Cash (BCH) $ 574.36
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 90,241.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,358.78
  • usdsUSDS (USDS) $ 1.00
  • chainlinkChainlink (LINK) $ 13.79
  • wrapped-eethWrapped eETH (WEETH) $ 3,352.74
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • leo-tokenLEO Token (LEO) $ 9.52
  • wethWETH (WETH) $ 3,095.64
  • stellarStellar (XLM) $ 0.238753
  • zcashZcash (ZEC) $ 464.69
  • hyperliquidHyperliquid (HYPE) $ 28.05
  • moneroMonero (XMR) $ 411.02
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 90,377.00
  • ethena-usdeEthena USDe (USDE) $ 0.999249
  • litecoinLitecoin (LTC) $ 81.88
  • suiSui (SUI) $ 1.59
  • avalanche-2Avalanche (AVAX) $ 13.35
  • hedera-hashgraphHedera (HBAR) $ 0.124530
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • susdssUSDS (SUSDS) $ 1.08
  • usdt0USDT0 (USDT0) $ 0.999941
  • daiDai (DAI) $ 0.999622
  • mantleMantle (MNT) $ 1.24
  • the-open-networkToncoin (TON) $ 1.61
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.144084
  • paypal-usdPayPal USD (PYUSD) $ 0.999747
  • crypto-com-chainCronos (CRO) $ 0.100024
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • uniswapUniswap (UNI) $ 5.44
  • polkadotPolkadot (DOT) $ 2.04
  • aaveAave (AAVE) $ 195.69
  • bittensorBittensor (TAO) $ 292.02
  • memecoreMemeCore (M) $ 1.63
  • usd1-wlfiUSD1 (USD1) $ 0.999104
  • canton-networkCanton (CC) $ 0.070608
  • bitget-tokenBitget Token (BGB) $ 3.60
  • rainRain (RAIN) $ 0.007426
  • okbOKB (OKB) $ 114.85
  • tether-goldTether Gold (XAUT) $ 4,310.35
  • falcon-financeFalcon USD (USDF) $ 0.998947
  • nearNEAR Protocol (NEAR) $ 1.65
  • ethereum-classicEthereum Classic (ETC) $ 13.17
  • aster-2Aster (ASTER) $ 0.950212
  • ethenaEthena (ENA) $ 0.249665
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,096.15
  • jito-staked-solJito Staked SOL (JITOSOL) $ 166.04
  • pepePepe (PEPE) $ 0.000004
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • internet-computerInternet Computer (ICP) $ 3.25
  • pi-networkPi Network (PI) $ 0.208312
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.66
  • pump-funPump.fun (PUMP) $ 0.002760
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • hash-2Provenance Blockchain (HASH) $ 0.030304
  • htx-daoHTX DAO (HTX) $ 0.000002
  • pax-goldPAX Gold (PAXG) $ 4,317.16
  • ondo-financeOndo (ONDO) $ 0.461275
  • worldcoin-wldWorldcoin (WLD) $ 0.585778
  • global-dollarGlobal Dollar (USDG) $ 0.999870
  • kucoin-sharesKuCoin (KCS) $ 10.66
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • bfusdBFUSD (BFUSD) $ 0.999263
  • skySky (SKY) $ 0.057588
  • ripple-usdRipple USD (RLUSD) $ 0.999684
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,557.35
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999822
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.120796
  • aptosAptos (APT) $ 1.66
  • kaspaKaspa (KAS) $ 0.046015
  • gatechain-tokenGate (GT) $ 10.37
  • wbnbWrapped BNB (WBNB) $ 886.55
  • arbitrumArbitrum (ARB) $ 0.208419
  • binance-staked-solBinance Staked SOL (BNSOL) $ 144.70
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,281.57
  • official-trumpOfficial Trump (TRUMP) $ 5.59
  • algorandAlgorand (ALGO) $ 0.122460
  • ignition-fbtcFunction FBTC (FBTC) $ 89,986.00
  • cosmosCosmos Hub (ATOM) $ 2.17
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,314.85
  • vechainVeChain (VET) $ 0.011760
  • flare-networksFlare (FLR) $ 0.012487
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 90,380.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 90,284.00
  • filecoinFilecoin (FIL) $ 1.34
  • nexoNEXO (NEXO) $ 0.974208
  • xdce-crowd-saleXDC Network (XDC) $ 0.049196
  • midnight-3Midnight (NIGHT) $ 0.051934
  • usdtbUSDtb (USDTB) $ 0.999875
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.92
  • sei-networkSei (SEI) $ 0.129452
  • ousgOUSG (OUSG) $ 113.62
  • render-tokenRender (RENDER) $ 1.55
  • bonkBonk (BONK) $ 0.000009
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999959
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 28.24
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.22
  • usddUSDD (USDD) $ 1.00
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 90,128.00
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,335.82
  • wrapped-flareWrapped Flare (WFLR) $ 0.012481
  • clbtcclBTC (CLBTC) $ 90,593.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998802
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010956
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • ultimaUltima (ULTIMA) $ 6,786.33
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999804
  • beldexBeldex (BDX) $ 0.088122
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,300.05
  • usdaiUSDai (USDAI) $ 0.999973
  • jupiter-exchange-solanaJupiter (JUP) $ 0.205235
  • story-2Story (IP) $ 1.90
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 153.87
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999793
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.240315
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,096.25
  • morphoMorpho (MORPHO) $ 1.15
  • optimismOptimism (OP) $ 0.311782
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,207.17
  • myx-financeMYX Finance (MYX) $ 3.10
  • dashDash (DASH) $ 46.29
  • curve-dao-tokenCurve DAO (CRV) $ 0.400561
  • spx6900SPX6900 (SPX) $ 0.594064
  • aerodrome-financeAerodrome Finance (AERO) $ 0.607424
  • tbtctBTC (TBTC) $ 90,226.00
  • usual-usdUsual USD (USD0) $ 0.996213
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,095.63
  • injective-protocolInjective (INJ) $ 5.40
  • tezosTezos (XTZ) $ 0.499780
  • lido-daoLido DAO (LDO) $ 0.596551
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.806620
  • bridged-wrapped-ether-pundi-aifx-omnilayerBridged Wrapped Ether (Pundi AIFX Omnilayer) (WETH) $ 35,382,014.00
  • blockstackStacks (STX) $ 0.288118
  • starknetStarknet (STRK) $ 0.105314
  • celestiaCelestia (TIA) $ 0.587135
  • gtethGTETH (GTETH) $ 3,096.36
  • true-usdTrueUSD (TUSD) $ 0.996523
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 2,460.42
  • ether-fiEther.fi (ETHFI) $ 0.806730
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • newton-projectAB (AB) $ 0.005256
  • msolMarinade Staked SOL (MSOL) $ 178.92
  • telcoinTelcoin (TEL) $ 0.004898
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.230723
  • stader-ethxStader ETHx (ETHX) $ 3,332.55
  • ghoGHO (GHO) $ 0.999958
  • merlin-chainMerlin Chain (MERL) $ 0.436711
  • flokiFLOKI (FLOKI) $ 0.000047
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,275.92
  • the-graphThe Graph (GRT) $ 0.041340
  • kaiaKaia (KAIA) $ 0.074850
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.991542
  • iotaIOTA (IOTA) $ 0.100851
  • doublezeroDoubleZero (2Z) $ 0.121386
  • basic-attention-tokenBasic Attention (BAT) $ 0.281757
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.89
  • swethSwell Ethereum (SWETH) $ 3,405.58
  • bittorrentBitTorrent (BTT) $ 0.00000041
  • sbtc-2sBTC (SBTC) $ 93,007.00
  • usdbUSDB (USDB) $ 1.00
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.965302
  • dogwifcoindogwifhat (WIF) $ 0.398991
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,444.67
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • bitcoin-svBitcoin SV (BSV) $ 19.77
  • sun-tokenSun Token (SUN) $ 0.020341
  • lorenzo-wrapped-bitcoinLorenzo Wrapped Bitcoin (ENZOBTC) $ 90,454.00
  • justJUST (JST) $ 0.038055
  • pyth-networkPyth Network (PYTH) $ 0.064972
  • conflux-tokenConflux (CFX) $ 0.071833
  • fartcoinFartcoin (FARTCOIN) $ 0.366663
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 90,167.00
  • olympusOlympus (OHM) $ 22.16
  • apenftAINFT (NFT) $ 0.00000036
  • pendlePendle (PENDLE) $ 2.18
  • crvusdcrvUSD (CRVUSD) $ 0.998585
  • decredDecred (DCR) $ 20.64
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.137771
  • audieraAudiera (BEAT) $ 2.51
  • theta-tokenTheta Network (THETA) $ 0.351635
  • the-sandboxThe Sandbox (SAND) $ 0.132892
  • sonic-3Sonic (S) $ 0.091264
  • heliumHelium (HNT) $ 1.84
  • chilizChiliz (CHZ) $ 0.033507

Rogue Developer Steals $785K in Roar Staking Contract Exploit

0 141

Rogue Developer Steals $785K in Roar Staking Contract Exploit

The staking contract associated with Roar was addressed, and a hacker drained over 785,000 from its staking pool when the staking pools were launched. The attacker used the emergencyWithdraw() flaw to withdraw 100 million $1ROR tokens immediately after staking rewards were deposited. Hacken, a prominent Web3 security auditor, was the first one to detect and report the details through its official social media platform, X account.

🚨 @th3r0ar Staking Exploit: $785K Stolen

A staking contract tied to Roar was exploited shortly after pools were created and rewards deposited.

The attacker abused a flaw in emergencyWithdraw(), specifically how withdrawal amounts were calculated, to drain 100M $1ROR – then… pic.twitter.com/CZNQA4kmU2

— Hacken🇺🇦 (@hackenclub) April 16, 2025

An early observation was made that the reward had a problem regarding calculating or miscalculating the withdrawal process. But after some research, it was found that the basic cause was the injection of some harmful code into the contract constructor. This constructor preset a staking amount for the attacker’s wallet address at deployment. This preloaded value enabled the wallet to withdraw tokens without staking tokens on multiple occasions in the first place.

Rogue Developer Behind the Incident

Yehor Rudytsia, the on-chain security researcher, analyzed the whole incident and shared his comments with the crypto community. The exploit was initiated after Roar staked rewards, after which assets were provided on the decentralized exchanges. The extracted tokens were subsequently exchanged to ETH and the funds were split among several wallet addresses simultaneously. Transactions were passed through Tornado Cash to ensure that laundering was almost invisible.

Roar stated that this attack was not carried out by an outsider but by an internal developer who exploited a process meant for early-version bug testing. The attackers remained dormant for 17 days after the signs of attack were evident, save for one attack witnessed by the investigators. This timing helped the hackers obtain sufficient market depth to sell the stolen tokens back to ETH without much price impact.

The investigators revealed that the developer preset the balance when creating the contracts. Consequently, the attacker was able to control the withdrawal function from the very start of the process. It was not an error missed while coding the second version of the app but a deliberate action by someone who had access.

Attacker Used Tornado Cash to Obscure Initial Funding Trail

The wallet procured its initial capital through Tornado Cash, which shows the subject’s desire to mask operations. Once the staking contract was empty, the attacker split and attempted to transfer the ejected tokens to different chains and wallet addresses.

Security experts also pointed out that it was not a technical vulnerability in the platforms but an operationally exploitable one. Yehor Rudytsia, the security researcher from Hacken also expressed that excessive trust in individual developers should be minimized in relation to internal controls and clear deployment specifications. He also stated,

“Projects need to implement reproducible builds, enforce separation between developers and deployers, and validate that deployed bytecode matches the audited source. But beyond that, orgs should treat dev access like a live attack surface: monitor credentials, watch for anomalies, and never store secrets in plaintext.”

Source

Leave A Reply

Your email address will not be published.