Sep 2024 - Omnipus Presale Contract Vulnerability Refund - $30k (Global)

"Omnipus is a sigma pirate lord hailing from the once pumping kingdom of Ethereum. But Ethereum is in crisis. Plagued by overpopulation and strained resources, it’s community has splintered. These fractured communities have formed their own Layer-2 factions.
A new threat brews in the South: a mischievous pirate, Sqwob, hailing from the land of Solania. With their hive-mind thirst for number go up, Sqwob & his minions plague the kingdom and threaten the future of decentralisation.
Omnipus is on a mission to unite the factions of his beloved community, thwart Sqwob & make Ethereum great again."
"As a LayerZero OFT, $OPUS maintains a unified supply across deployed chains.
A 0.5% fee is charged on all bridging, and this loot is fed back into the coffers of stakers.
Additionally, 20% of $OPUS supply will be locked & paid out in staking rewards over a 2-year period."
"30% of total $OPUS supply is reserved for the presale.
The presale is priced on a Bonding Curve. As more tokens are sold, the price increases. Simply, early users receive more $OPUS for a lower price.
The presale will run for fixed amount of time. Any presale tokens not sold will be burned at the end of the presale."
"Omnipus contracts were drained of approximately $30,000 during the OPUS token presale. The attack exploited a vulnerability in which the contracts mistakenly believed the attackers had sent too much ETH and refunded them."
"We have identified a vulnerability in the smart contract & have subsequently halted presale Anyone invested in the presale has been fully refunded - further updates to follow"
Further Analysis
Omnipus is an token which can be used in any ethereum layer 2 protocols, at the specific exclusion of Solana. Omnipus launched a presale on Twitter. The next day, they posted an announcement about a vulnerability which was identified and announced that all users had been refunded. Slowmist reports an issue with the refund mechanism in the smart contract. Specific details about the vulnerability have not been published. It is unclear if the project will relaunch as the website still announces a presale launch date of September 8th.
How Could This Have Been Prevented?
More Cryptocurrency Exchange Hacks/Scams/Frauds
OTSea Gray Hat Group Staking ID Hack > > < < Indodax Withdrawal System Exploited
Sources/Further Reading
https://archive.ph/0LQSo (Dec 31)
@Omnipus_X Twitter (Dec 31)
@Omnipus_X Twitter (Dec 31)
Omnipus (Dec 31)
Omnipus (Dec 31)
t.me/QuadrigaInitiative
|
/r/QuadrigaInitiative
|
@QuadrigaInit
|
info@quadrigainitiative.com
|
t.me/QuadrigaInitiative
/r/QuadrigaInitiative
@QuadrigaInit
info@quadrigainitiative.com