Share this article

Cross-Chain DEX Rubic Loses Over $1M in Funds After Hackers Gain Access to Private Keys

Developers suspect the attackers accessed the admin wallet's private keys using malicious software.

Around 34 million RBC and BRBC tokens were sold on Uniswap and PancakeSwap. (Shutterstock)
Around 34 million RBC and BRBC tokens were sold on Uniswap and PancakeSwap. (Shutterstock)

Rubic, a service that allows users to swap cryptocurrencies between different exchanges, was exploited earlier Wednesday after attackers gained access to the private keys of an administrator's wallet.

“One of our admin’s wallet addresses was compromised. This wallet managed the RBC/BRBC bridge and staking rewards,” developers said in a tweet during morning hours in Asia. “We suspect it was malicious software that was used to get access to the admin wallet's private keys.”

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

A private key is a secret number that is used in cryptography, similar to a password. In cryptocurrency, private keys are also used to sign transactions and prove ownership of a blockchain address.

Around 34 million RBC and BRBC tokens were sold on the Uniswap and PancakeSwap exchanges. As such, Rubic continues to work without interruption and all user funds are safe. No contracts were exploited.

The 34 million RBC transferred out by the attackers was worth over $1.2 million at press time. Separately, the attacker's wallet flagged by Rubic in a tweet held over 205 BNB, or just over $65,000, in a BNB Chain wallet and over $205,000 worth of ether in an Ethereum wallet.

RBC prices plunged over 98% in the hours following the attack as the attackers sold all stolen tokens en masse. Prices bounced during European morning hours.

Shaurya Malwa

Shaurya is the Co-Leader of the CoinDesk tokens and data team in Asia with a focus on crypto derivatives, DeFi, market microstructure, and protocol analysis.

Shaurya holds over $1,000 in BTC, ETH, SOL, AVAX, SUSHI, CRV, NEAR, YFI, YFII, SHIB, DOGE, USDT, USDC, BNB, MANA, MLN, LINK, XMR, ALGO, VET, CAKE, AAVE, COMP, ROOK, TRX, SNX, RUNE, FTM, ZIL, KSM, ENJ, CKB, JOE, GHST, PERP, BTRFLY, OHM, BANANA, ROME, BURGER, SPIRIT, and ORCA.

He provides over $1,000 to liquidity pools on Compound, Curve, SushiSwap, PancakeSwap, BurgerSwap, Orca, AnySwap, SpiritSwap, Rook Protocol, Yearn Finance, Synthetix, Harvest, Redacted Cartel, OlympusDAO, Rome, Trader Joe, and SUN.

Shaurya Malwa