The Harmony team has published the following Medium article. Updates will be provided within the article below as the team's investigation continues.
Harmony’s Horizon Bridge Hack on Thursday, June 23, 2022
Below is an excerpt from the above article:
Update #1 [June 24th, 2022]
At 10:05am PST, the team announced that they have handed their findings to our US colleagues at 830am PST today. The team is comprised of members across 5 timezones and continues to their work at this time.
Link to official tweet from Harmony
[June 23rd, 2022]
On Thursday, June 23, 2022, the Harmony Protocol team was notified of a malicious attack on our proprietary Horizon Ethereum Bridge. At 5:30 AM PST, multiple transactions occurred that compromised the bridge with 11 transactions that extracted tokens stored in the bridge. The estimated value at the time of the attack was approximately $100 million USD.
Culprit 0x Address: 0x0d043128146654c7683fbf30ac98d7b2285ded00
Immediately following the attack, multiple cyber security partners, exchange partners, and the FBI were notified and requested to assist with an investigation in identifying the culprit and methods to retrieve stolen assets. With those contacts established, Harmony announced the hack via Twitter (link below) with a description of what occurred and our next steps.
Further, the team has attempted communication with the hacker with an embedded message in a transaction to the culprit’s address (above) at approximately 5:30 PM PST.
A complete breakdown will be provided at the conclusion of this investigation.
Harmony believes that focusing on decentralized bridges is an essential step forward for Web3. This incident is a humbling and unfortunate reminder of how our work is paramount to the future of this space, and how much of our work remains ahead of us.
Ongoing investigations present a challenge of what information is allowed to be shared with the public, but we will continue to provide updates with the latest information as soon as we are able to share.
This article will be regularly updated with the latest information, and will be provided via our Twitter and other social platforms. The goal is to continue providing regular updates throughout this process to keep everyone informed.
We are working around the clock to ensure both the investigation and recovery of stolen funds are concluded in the most time efficient manner possible.