Hacker loses 5 ETH in failed Rainbow Bridge attack

Rainbow Bridge Hacker Loses 5 ETH

The hacker, who attempted to attack Near Protocol's Rainbow Bridge, was discovered by Aurora Lab's security systems and lost 5 ETH in the process, worth $8.000.

The bridges between blockchains have been one of the main targets of hackers over the past few months. From the attack on Ronin, the Axie Infinity sidechain, which managed to steal $625 million, to the recent attack on Horizon, Harmony's bridge, which made off with $100 million, the bridges are in the crosshairs of malicious actors.

Rainbow Bridge, the bridge of Near Protocol, It was the latest to suffer one of these attacks over the weekend. However, this time the security systems worked properly and managed to stop the attack, keeping 5 ETH from the attacker, worth approximately $8.000.

The failed attack on Rainbow Bridge

This weekend's attack is not the first time Rainbow Bridge has been attacked, as the bridge was attacked for the first time in May. 

Just as it happened in that first attack, the cybersecurity and defense systems of the bridge Near-Protocol were activated and It took just 31 seconds to detect and stop the attack.

Alex Sevchenko, CEO of Aurora Labs, the developers of the bridge, explained on Twitter that the bridge's defense systems had worked correctly and that No user funds were lost in the attackOn the contrary, it was the attacker himself who lost 5 ETH.

The Rainbow Bridge allows users to transact between the light client of Near-Protocol, Ethereum and Aurora, creating interactions directly with smart contracts.

This way, if someone sends incorrect information to the NEAR light client, all funds on the Rainbow Bridge can be drained. To prevent this, the bridge uses a consensus of NEAR validators who analyze incoming information, together with an automatic surveillance system.

According to Sevchenko, the hacker attempted to send a fake Near Protocol block to the bridge and deposited the 5 ETH as collateral necessary to activate the operation. The attack took place early on Saturday, as the hacker expected that there would not be too many active nodes at that time.

However, Rainbow's automatic surveillance detected the malicious transaction and blocked it, keeping the 5 ETH that the attacker had deposited, preventing the loss of user funds.

Blockchain bridges targeted by hackers

As we have already explained, Rainbow Bridge was hit by a similar attack, in which a fake block was sent, in May. The attack was also discovered and repelled by Rainbow Bridge’s automatic defense system, causing the attacker to lose 2,5 ETH.

Bridges have become a favorite target for hackers, as contain the assets that back the tokens circulating on other chains

Earlier this month, an attack on the Nomad Bridge managed to steal $200 million by taking advantage of an exploit in one of the smart contracts. Last month, an attack on the Nomad Bridge Harmony's Horizon made off with $100 million, and in March, the attack on Axie Infinity's Ronin Bridge took $625 million.

[hubspot type=cta portal=20298209 id=38fb28e1-1dc1-40e3-9098-5704ca7fcb07]