96 private keys stolen from Vulcan Forged in $140 million theft

Quick Take

  • Vulcan Forged is a crypto gaming ecosystem, which creates wallets on behalf of its users.
  • An attacker accessed 96 of these wallets, stealing 23.7% of the project’s circulating supply of tokens.
  • So far, half of the funds have been reimbursed from the project’s treasury.

Earlier today, 96 private keys were stolen from the crypto gaming ecosystem Vulcan Forged, enabling the attacker to siphon off $140 million in cryptocurrency.

Vulcan Forged offers a smorgasbord of crypto activities. It is primarily a game studio, offering six different blockchain-based games. But it also has an NFT marketplace and its own decentralized exchange, where users can trade its token PYR.

When someone registers an account with Vulcan Forged, the platform creates a set of blockchain wallets for them on the Ethereum, Polygon and VeChain blockchains. Rather than have the user manage their own private keys, the platform does so on their behalf. 

According to the project’s own wiki, it works with wallet management service Venly (formerly Arkane Network) to create its wallets — a service also used by Atari, Matic and the Blockchain Game Alliance. 

"Venly Servers or Solutions have not been compromised. The Venly team is actively helping the Vulcan Forged team with data analytics to help them understand and recover from this unfortunate event. Official communication will follow soon." said Venly CEO Tim Dierckxens.

Dumping the tokens on Uniswap

The 96 wallets that were affected contained 4.5 million PYR, worth $140 million at the time of the attack. That’s 9% of the project’s total supply of tokens, according to CoinGecko, and 23.7% of the circulating supply. Other assets including ether (ETH) and polygon (MATIC) may have also been taken.

After the exploit was discovered — but before it was announced — Vulcan Forged told its community to remove funds from the liquidity pools on decentralized exchanges. This would make it harder for the attacker to cash out the funds, without using centralized exchanges where they might need identity documents.

THE SCOOP

Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

Despite this, the attacker has sold significant amounts of PYR for ETH, selling small batches of tokens at a time. But they still have 2 million PYR (currently worth $47 million) sitting untouched in one wallet.

This selling pressure has dropped the price of PYR. It was at $31 prior to the attack and is now at $24 — down 22%.

Vulcan Forged has said the project’s treasury will send out PYR and Vulcan Forged’s LAVA tokens to those affected. They will need to set up accounts with MetaMask and will receive the tokens there. Anyone who had ETH or MATIC stolen will receive the equivalent amount in PYR. So far, half of the funds have been reimbursed.

“We have contacted all exchanges to blacklist that address. It also seems the wallet owner may have KYCd [completed Know Your Customer checks] on an exchange we’re now in contact with,” tweeted Vulcan Forged.

It added that it is removing what it described as a semi-custodial solution from the Vulcan Forged ecosystem — meaning that in the future, its users will need to look after their own private keys.

For more breaking stories like this, make sure to follow The Block on Twitter.


© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Author

Tim is the Editor-In-Chief of The Block. Prior to joining The Block, Tim was a news editor at Decrypt. He has earned a bachelor's degree in philosophy from the University of York and studied news journalism at Press Association Training. Follow him on X @Timccopeland.