Concentric app suffers $1.7m social engineering hack on Arbitrum
The liquidity manager app Concentric experienced a significant security breach today on the Arbitrum network. The breach involved a social engineering attack that enabled the unauthorized acquisition of a critical private key. This key belonged to the protocol’s deployment account and was instrumental in the attack. During the incident, the perpetrator managed to manipulate the protocol by upgrading the vaults and creating new liquidity provider (LP) tokens. This series of actions ultimately led to the extraction of assets from the vaults. Exploiter is now targeting approvals on vaults, please revoke all approvals to these addresses:https://t.co/3vTEWu23BJ https://t.co/KlZo5PqjlI — Concentric.fi (@ConcentricFi) January 22, 2024 The breach was executed by gaining control of an employee’s deployer wallet on Arbitrum. The $1.7 million in stolen funds were converted into Ethereum and dispersed across three wallet addresses. Cybersecurity company Cyvers detec...