A real hack happened in a 0xDeadList address!

TLDR: When 0xDeadList Dev team transfers some Matic to a leaked address. A hack happened after a while.

The hack:

https://polygonscan.com/tx/0x8539ba8f0d5a55273108432578f77b92a66a22dbeb80032940d33c08926e86bd

To test the dark forest of Ethereum, and also to encourage hackers to report their hacked addresses. We airdrop one of the 0xDeadList addresses in Polygon:

https://polygonscan.com/address/0x40d0308215956928dc67cfaa76202d0f9694e003

We choose this address for the following reasons:

  1. It has not been buried in the Polygon mainnet before the hack happened.

  2. The 0xDeadList Dev team used this account to test the 0xDeadList contract, and the account has been buried during the test. For example, the account has been sent a tombstone SBT (with its private key in the ERC-721 Token ID), see this transaction for more details:

    https://rinkeby.etherscan.io/tx/0x6473db20f9b341745becde9811c331befff1a95bae7427f66929b815b209128e

We think that it’s harder for hackers to find this leaked address, but let’s see what happened before the hack:

  1. The address has been leaked 100 days ago (buried in Rinkeby), and first has a balance in Polygon 90 days ago (5 Matic). Although we have no idea when hackers found this leaked address, the hack never happened until yesterday.

  2. We transfer 0.616 ETH to this address (transaction 1) and nothing happened.

  3. We swap the 0.616 ETH into 966.905 Matic (transaction 2) in block height 34675224, and after 3 blocks (block height 34675227), a hacker has stolen all 970 Matic (transaction 3).

Is it interesting? Welcome to find more details about this hack and discuss it with us in our Discord.

https://discord.gg/WMZdx5hbr2