An attacker maliciously upgraded the Parallel parachain runtime, granting themselves administrative privileges. This allowed them to steal over 312,185 DOT and 126,837 USDT. The attacker is actively unbonding approximately 125,688 DOT, putting additional capital at risk in 4 days. Immediate action is required to vote on a referendum supported by Parity to recover the stolen assets within the next 4 days. The goal is to secure 112M votes with conviction to prevent further losses. Currently, 26.7M votes have been collected.
Huobi Deposit Records
https://polkadot.subscan.io/extrinsic/23562969-3 3700 DOT https://polkadot.subscan.io/extrinsic/23562717-3 10000 DOT https://polkadot.subscan.io/extrinsic/23562419-3 3700 DOT https://polkadot.subscan.io/extrinsic/23562021-2 3700 DOT https://polkadot.subscan.io/extrinsic/23561741-2 3700 DOT https://polkadot.subscan.io/extrinsic/23555165-3 3700 DOT https://polkadot.subscan.io/extrinsic/23554898-2 3700 DOT https://polkadot.subscan.io/extrinsic/23553897-2 3700 DOT https://polkadot.subscan.io/extrinsic/23553675-2 1850 DOT https://polkadot.subscan.io/extrinsic/23580038-3 1000 DOT https://polkadot.subscan.io/extrinsic/23585399-3 3700 DOT https://polkadot.subscan.io/extrinsic/23585574-2 3700 DOT https://polkadot.subscan.io/extrinsic/23586196-3 1000 DOT https://polkadot.subscan.io/extrinsic/23585999-2 1000 DOT https://polkadot.subscan.io/extrinsic/23585855-2 1000 DOT
Binance Deposit Records
https://polkadot.subscan.io/extrinsic/23562402-6 3700 DOT https://polkadot.subscan.io/extrinsic/23562002-8 3700 DOT https://polkadot.subscan.io/extrinsic/23561704-10 3700 DOT https://polkadot.subscan.io/extrinsic/23555169-3 3700 DOT https://polkadot.subscan.io/extrinsic/23554861-4 3700 DOT https://polkadot.subscan.io/extrinsic/23554219-2 1850 DOT https://polkadot.subscan.io/extrinsic/23593355-2 3700 DOT
FixedFloat Deposit Records
https://polkadot.subscan.io/extrinsic/23562687-4 3500 DOT https://polkadot.subscan.io/extrinsic/23562374-3 3500 DOT https://polkadot.subscan.io/extrinsic/23561976-9 3500 DOT https://polkadot.subscan.io/extrinsic/23561712-3 3500 DOT https://polkadot.subscan.io/extrinsic/23553463-2 3700 DOT https://polkadot.subscan.io/extrinsic/23553419-3 3700 DOT https://polkadot.subscan.io/extrinsic/23553390-3 3700 DOT https://polkadot.subscan.io/extrinsic/23316953-2 1000 DOT https://polkadot.subscan.io/extrinsic/23316293-2 4000 DOT https://polkadot.subscan.io/extrinsic/23316253-2 1000 DOT https://polkadot.subscan.io/extrinsic/23316236-2 1000 DOT https://polkadot.subscan.io/extrinsic/23316212-2 1000 DOT https://polkadot.subscan.io/extrinsic/23316188-3 1000 DOT https://polkadot.subscan.io/extrinsic/23316147-2 1000 DOT https://polkadot.subscan.io/extrinsic/23316089-2 1000 DOT https://polkadot.subscan.io/extrinsic/23316067-2 1000 DOT https://polkadot.subscan.io/extrinsic/23316041-2 1000 DOT https://polkadot.subscan.io/extrinsic/23580021-2 1000 DOT https://polkadot.subscan.io/extrinsic/23585215-2 3700 DOT https://polkadot.subscan.io/extrinsic/23585498-3 3700 DOT https://polkadot.subscan.io/extrinsic/23594996-2 100 DOT https://polkadot.subscan.io/extrinsic/23595014-2 1000 DOT https://polkadot.subscan.io/extrinsic/23595037-2 1000 DOT https://polkadot.subscan.io/extrinsic/23595068-3 1000 DOT https://polkadot.subscan.io/extrinsic/23609031-2 3000 DOT (11/28)
WhiteBit Deposit Records
https://polkadot.subscan.io/extrinsic/23466096-4 3000 DOT https://polkadot.subscan.io/extrinsic/23465666-3 3000 DOT https://polkadot.subscan.io/extrinsic/23464980-3 3000 DOT https://polkadot.subscan.io/extrinsic/23317105-2 4000 DOT https://polkadot.subscan.io/extrinsic/23316529-2 3000 DOT https://polkadot.subscan.io/extrinsic/23579972-2 1000 DOT https://polkadot.subscan.io/extrinsic/23585207-3 3700 DOT
To obfuscate the trail, the attacker moved assets across chains
https://polkadot.subscan.io/extrinsic/23594945-2 The hacker first deposited 10,003 DOT to a new address on the Acala parachain: 22EZbDcLVkeGRPsRFRTbWpHAi3tLymN3unv6tpnhqsLiaPkV
https://acala.subscan.io/xcm_message/polkadot-200c01df2b59ce87981452eb50e05799726f3b91 Next, it was cross-chained from the Acala parachain to another new address 12My1JCJeqtzropnC6fMjocvFCTQRw4r2PNnjzMhDKPqkuhM on Polkadot via XCM communication At the new address, the hacker deposited to the exchange again.
https://polkadot.subscan.io/extrinsic/23594996-2 100 DOT FixedFloat https://polkadot.subscan.io/extrinsic/23595014-2 1000 DOT FixedFloat https://polkadot.subscan.io/extrinsic/23595037-2 1000 DOT FixedFloat https://polkadot.subscan.io/extrinsic/23595068-3 1000 DOT FixedFloat https://polkadot.subscan.io/extrinsic/23595978-3 Finally, the hacker transferred the remaining 7,000 DOT back to the initial hacker address. Note: The hacker may subsequently use similar actions to "obfuscate the trail" by creating more new addresses to evade monitoring (possibly involving other parachains in the Polkadot ecosystem).
Moving all DOT to Ethereum
https://moonscan.io/address/0xf6b852758a34c31641994ca6b4357b34ad1c18dc#tokentxns DOT-Moonbeam-Squidrouter https://etherscan.io/tx/0x3d131a8f255e8a1b7a991f9b3a607ac550c1b5275917d147488c6d3f918da805 swap to BTC https://etherscan.io/address/0xf6b852758a34c31641994ca6b4357b34ad1c18dc#internaltx All DOT move to Ethereum account
The community must urgently vote on the referendum to recover stolen assets within the next 4 days. Securing 112M votes with conviction is critical to prevent further losses and long-term damage to the ecosystem.
In the past 24 hours, the hacker transferred all remaining DOT to Moonbeam and used cross-chain bridges to move the funds to Ethereum. The hacker now holds close to a zero balance on Polkadot.
We strongly urge the community to vote on the proposal to recover and rebond the remaining 125,000+ DOT as quickly as possible and regain control of the parachain.