Memos to the Resupply exploiter

On-chain memos sent to the Resupply exploiter after the June 2025 ~$9.5M hack.

Source: halborn.com

Hello, we understand that you recently carried out a transaction on Resupply that led to the protocol’s shortfall of 10M reUSD. Your skills are clear to anyone reviewing the transaction—it was very well-executed, and your actions surfaced a critical code flaw. Code improvements as a result of this event are currently under audit and will result in hardening of the protocol. We are reaching out again, as we see that you still have not moved the ETH bought using reUSD. Our offer to you: return 80% of the ETH to Resupply’s multisig, 0xFE11a5009f2121622271e7dd0FD470264e076af6, keeping 20% as a whitehat bounty. Alternatively, return 10M USDC and keep the remainder as the whitehat bounty. In return, we will cease our investigations and those we've arranged with third parties, as well as our current engagement with law enforcement. This offer expires 1 week from the timestamp of this message. By accepting the whitehat bounty, you would significantly reduce the risk you take when utilizing these funds in the future. The protocol and its users will have been made fully whole, with no remaining reason to pursue you. You can contact us in multiple ways Email: contact@resupply.fi Resupply Deployer 1: 0x1101c94c6001e4074Ad4dBAd5Ad08117979cA9D4 (onchain or via encrypted Blockscan chat) We look forward to speaking with you and urge you to do the right thing.
Public statement to Resupply protocol attackers Respected attacker, We are the development team of the Resupply protocol. On June 26, 2025, you took advantage of the loophole in the ResupplyPair contract to illegally transferred about $9.5 million to $9.6 million in digital assets. We have locked your IP address through the front-end UI of CowSwap and KyberSwap, and collected complete evidence of relevant on-chain activity. We would like to propose the following plans to you: Return the stolen funds immediately, and we will provide a 20% white hat bonus (calculated according to ETH) as a reward, and promise not to hold you accountable. Please transfer the stolen funds to the project vault address: 0xc1FdE923925d212996B6C59415848F36Cc170f90 within 72 hours (as of 12:00 AM UTC on July 3, 2025). We are willing to solve this matter in a cooperative manner and protect the interests of all relevant parties. If you choose to refuse cooperation, we will take the following actions: 1. Use the available IP addresses, on-chain transaction records and other forensic data to fully cooperate with global law enforcement agencies to carry out investigations. 2. Initiate legal procedures to trace your identity and assets through international judicial cooperation. 3. Disclose all relevant information in the blockchain community to further limit the possibility of transferring or using stolen funds. We strongly recommend that you choose to return the funds and accept the white hat bonus, which will provide you with a decent solution while avoiding further legal and reputational risks. Resupply is committed to protecting the interests of users and communities, and we hope to solve problems through cooperation rather than confrontation. Resupply Development Team June 30, 2025
Public statement to Resupply protocol attackers Respected attacker, We are the development team of the Resupply protocol. On June 26, 2025, you took advantage of the loophole in the ResupplyPair contract to illegally transferred about $9.5 million to $9.6 million in digital assets. We have locked your IP address through the front-end UI of CowSwap and KyberSwap, and collected complete evidence of relevant on-chain activity. We would like to propose the following plans to you: Return the stolen funds immediately, and we will provide a 20% white hat bonus (calculated according to ETH) as a reward, and promise not to hold you accountable. Please transfer the stolen funds to the project vault address: 0xc1FdE923925d212996B6C59415848F36Cc170f90 within 72 hours (as of 12:00 AM UTC on July 3, 2025). We are willing to solve this matter in a cooperative manner and protect the interests of all relevant parties. If you choose to refuse cooperation, we will take the following actions: 1. Use the available IP addresses, on-chain transaction records and other forensic data to fully cooperate with global law enforcement agencies to carry out investigations. 2. Initiate legal procedures to trace your identity and assets through international judicial cooperation. 3. Disclose all relevant information in the blockchain community to further limit the possibility of transferring or using stolen funds. We strongly recommend that you choose to return the funds and accept the white hat bonus, which will provide you with a decent solution while avoiding further legal and reputational risks. Resupply is committed to protecting the interests of users and communities, and we hope to solve problems through cooperation rather than confrontation. Resupply Development Team June 30, 2025