0x9098…9673

All memos sent from and to 0x9098…9673.

Balancer DAO — Notice to wallet owner: We understand this wallet is linked to the exploit of Balancer V2 Composable Stable Pools on Nov 3rd. We are treating this as an opportunity for cooperation and would prefer to resolve this without escalation. If you are willing to cooperate, reply to this message and begin contact procedures before November 8th, 21:00 UTC. If we do not hear from you by that time, we will assume you are unwilling to help make the liquidity providers whole and will escalate our response. We would like to extend you an offer: return the funds to the DAO multisig address in exchange for a bounty. The details of this offer shall be arranged privately. Upon verification that the returned funds meet the criterias, Balancer will not pursue legal action or investigative steps aimed at identifying or prosecuting the owner of the returning wallet that are based solely on the fact of the return. If you do not accept this offer or do not respond in time, we will use all technical, on-chain, and legal measures to identify and pursue the attacker. In that case, any bounty will instead be used to reward verified informants who help identify and lead to prosecution of the attacker. To proceed, respond to this message privately via Blockscan (https://chat.blockscan.com). After successful verification, all communications will be coordinated with SEAL911, Hypernative, and Balancer’s legal team.
Balancer DAO — Notice to wallet owner: We understand this wallet is linked to the exploit of Balancer V2 Composable Stable Pools on Nov 3rd. We are treating this as an opportunity for cooperation and would prefer to resolve this without escalation. If you are willing to cooperate, reply to this message and begin contact procedures before November 8th, 21:00 UTC. If we do not hear from you by that time, we will assume you are unwilling to help make the liquidity providers whole and will escalate our response. We would like to extend you an offer: return the funds to the DAO multisig address in exchange for a bounty. The details of this offer shall be arranged privately. Upon verification that the returned funds meet the criterias, Balancer will not pursue legal action or investigative steps aimed at identifying or prosecuting the owner of the returning wallet that are based solely on the fact of the return. If you do not accept this offer or do not respond in time, we will use all technical, on-chain, and legal measures to identify and pursue the attacker. In that case, any bounty will instead be used to reward verified informants who help identify and lead to prosecution of the attacker. To proceed, respond to this message privately via Blockscan (https://chat.blockscan.com). After successful verification, all communications will be coordinated with SEAL911, Hypernative, and Balancer’s legal team.
Balancer DAO — Notice to wallet owner: We understand this wallet is linked to the exploit of Balancer V2 Composable Stable Pools on Nov 3rd. We are treating this as an opportunity for cooperation and would prefer to resolve this without escalation. If you are willing to cooperate, reply to this message and begin contact procedures before November 8th, 21:00 UTC. If we do not hear from you by that time, we will assume you are unwilling to help make the liquidity providers whole and will escalate our response. We would like to extend you an offer: return the funds to the DAO multisig address in exchange for a bounty. The details of this offer shall be arranged privately. Upon verification that the returned funds meet the criterias, Balancer will not pursue legal action or investigative steps aimed at identifying or prosecuting the owner of the returning wallet that are based solely on the fact of the return. If you do not accept this offer or do not respond in time, we will use all technical, on-chain, and legal measures to identify and pursue the attacker. In that case, any bounty will instead be used to reward verified informants who help identify and lead to prosecution of the attacker. To proceed, respond to this message privately via Blockscan (https://chat.blockscan.com). After successful verification, all communications will be coordinated with SEAL911, Hypernative, and Balancer’s legal team.
You are right that no specific vote was passed by the DAO regarding refunds and how they would be technically made. We assumed the DAO will always send funds to rightful LPs as they are returned by hackers. This is obvious but has to be voted and agreed by the DAO officially. It's enough to know that you are going to return funds once more information is available about how the DAO will return them to rightful LPs. The DAO is likely going to deliberate on that soon so please be patient. Thanks for your collaboration.
And you mentioned "Balancer DAO has issued an on-chain statement to the attackers" in your twitter https://twitter.com/Balancer/status/1702706934980448578 on Sep 27, 2023, 3:32 UTC Can you point me to where your proposal is located and when it passed the vote to accept the 90% return of the funds and pay the 10% bonus from the DAO? You stated that the DAO is not controlled by developers, but from what I've seen, developers are represent the DAO even without voting, where the confidence come from if developers are not controlling the DAO? If you have a proposal that has been approved through DAO voting, please provide the details or a link to it, and I will promptly transfer the funds to your DAO multi-sig wallet. The point is a 10% bonus has been stated without any supporting evidence. Who will be responsible for covering this bonus – the Balancer team (you?), the DAO, or the affected LPs? If you are claiming to represent them, it's necessary to provide proof; otherwise, I may need to retain partial control over the funds until the situation is clarified.
Do you mean that the multi-sig wallet 0x10A19e7eE7d7F8a52822f6817de8ea18204F2e4f, controlled by 6 out of 11 Externally Owned Accounts (EOAs), is governed by DAO voting? Could you please explain how this works? I haven't heard how a multi-sig wallet can execute a proposal without signatures from the EOAs in this case. If you assert that these EOAs do not belong to developers, then let me correct my statement: I can't transfer affected user funds into a multi-sig wallet controlled by 6 out of 11 unknown entities without even a compensation proposal. Regarding the charges, the Balancer team should take full responsibility for the loss suffered by users due to the buggy code you deployed and the unqualified auditing firms you hired. The first exploit transaction occurred on August 27, 2023, at 07:52:23 UTC, and the exploit method was exposed thereafter. However, you took no action to rescue the funds, not even by copycatting, allowing the exploit to continue for several days until September 2, 2023. I have already presented my proposal and agreed to transfer affected funds to a multi-sig wallet owned together by your team. All the left I am requesting is a reasonable compensation proposal, which you seem unwilling to provide. I am curious, even if I were to transfer the funds to your 6 out of 11 multi-sig wallet now, without a compensation plan, what would you intend to do with them? If you insist on blustering via on-chain message instead of creating a multi-sig wallet and working on a compensation plan, I am prepared for your legal action, and I am ready to meet you in court. However, you shall find yourself in the defendant's seat also.
The DAO is not controlled by developers. All returned funds will be used to refund LPs, but how that will be done technically will have to be voted by the DAO. The offer and the deadline stand, after that charges will be pursued.
The total funds I am holding from this rescue are 3.374 + 3.427 = 6.801 ETH, converting from 5,578 + 5,681 = 11,259 USDC in transactions https://etherscan.io/tx/0x36f660abf2ac0175ca3f3f2bc939adb4b03704e5c324ddd5b4093f31fa2873bb and https://etherscan.io/tx/0x032bd01a59296bbbad40794b83951710a49780d90285ef3d3b8fbd455096d5ca. I will keep 10% (0.680 ETH) as a rescue bounty and need to request reimbursement for the gas consumed during this rescue from block 18007286 to 18013705, totaling 0.773 ETH. The final refund amount would be 6.801 - 0.680 - 0.773 = 5.348 ETH. For the remaining amount, the entities responsible for writing and auditing the buggy code that led to user funds being put at risk shall compensate. Although I don't believe that 5.348 ETH would have a significant impact on your compensation progress, since you've sent a formal request, let's formalize the rest of the process, as the funds belong to the affected LPs, not to a DAO controlled by the developers. Therefore, I can't simply send the funds to the address you request before I ensure that the compensation funds will be delivered to the affected LPs properly. If you agree with above statement and are planing to recover the losses to the affected users, please: 1. Create a Safe multi-sig wallet with 2/2 owners/threshold and put my address in one of the owners. 2. I commit to transferring the sum of 5.348 ETH upon the successful creation of said wallet. 3. However, I would only authorize the transaction to move these funds after the remaining compensation amount is deposited into the said wallet. 4. The funds receiver address should be the entity listed on your compensation plan/proposal. The plan/proposal should clearly outline how the recovered funds will be delivered, who will compensate for the uncovered funds, and which address will temporarily store the funds before they are delivered to the affected users. Any further questions or additional clarifications needed, please let me know.
You've probably already realized this and hoped we wouldn't, but: you made a small mistake. This has led to us being able to corroborate with some leads we received based on a tip, and we have finally narrowed the chase enough to feel confident sending this message on-chain. It's often the case that those who are very skilled in web3 (like you) make small mistakes in their opsec - web2 traces, or talking to people who they shouldn't about the attack. This is the case here too. So this will be our last message we send before we pursue charges: send back 90% of the stolen crypto to the Balancer DAO multisig 0x10A19e7eE7d7F8a52822f6817de8ea18204F2e4f, keep 10% for yourself as a bounty, and we will back off of our pursuit and you can live a free person who's quite a bit wealthier. We need the money back by UTC 0900 18 Sept. If it's not sent back by then, our offer of you keeping 10% is revoked, and we will involve the authorities who are awaiting our 'go ahead' as we speak. If you have any questions, email us at balancer.contact@protonmail.com - please sign any message with the address you hacked funds otherwise the email will be disregarded. We look forward to closing this situation out, you making some money, and us all going on our way without involving the centralized authorities any further.
You've probably already realized this and hoped we wouldn't, but: you made a small mistake. This has led to us being able to corroborate with some leads we received based on a tip, and we have finally narrowed the chase enough to feel confident sending this message on-chain. It's often the case that those who are very skilled in web3 (like you) make small mistakes in their opsec - web2 traces, or talking to people who they shouldn't about the attack. This is the case here too. So this will be our last message we send before we pursue charges: send back 90% of the stolen crypto to the Balancer DAO multisig 0x10A19e7eE7d7F8a52822f6817de8ea18204F2e4f, keep 10% for yourself as a bounty, and we will back off of our pursuit and you can live a free person who's quite a bit wealthier. We need the money back by UTC 0900 18 Sept. If it's not sent back by then, our offer of you keeping 10% is revoked, and we will involve the authorities who are awaiting our 'go ahead' as we speak. If you have any questions, email us at balancer.contact@protonmail.com - please sign any message with the address you hacked funds otherwise the email will be disregarded. We look forward to closing this situation out, you making some money, and us all going on our way without involving the centralized authorities any further.
You've probably already realized this and hoped we wouldn't, but: you made a small mistake. This has led to us being able to corroborate with some leads we received based on a tip, and we have finally narrowed the chase enough to feel confident sending this message on-chain. It's often the case that those who are very skilled in web3 (like you) make small mistakes in their opsec - web2 traces, or talking to people who they shouldn't about the attack. This is the case here too. So this will be our last message we send before we pursue charges: send back 90% of the stolen crypto to the Balancer DAO multisig 0x10A19e7eE7d7F8a52822f6817de8ea18204F2e4f, keep 10% for yourself as a bounty, and we will back off of our pursuit and you can live a free person who's quite a bit wealthier. We need the money back by UTC 0900 18 Sept. If it's not sent back by then, our offer of you keeping 10% is revoked, and we will involve the authorities who are awaiting our 'go ahead' as we speak. If you have any questions, email us at balancer.contact@protonmail.com - please sign any message with the address you hacked funds otherwise the email will be disregarded. We look forward to closing this situation out, you making some money, and us all going on our way without involving the centralized authorities any further.