Dear Osmosis Validators & Community,
I’m writing to you after making the biggest mistake of my life that has cost me ~$100K. 4 days ago I was the victim of a phishing scam which has led to me losing the vast majority of my crypto holdings. Usually in such a scenario - the funds are moved quickly off chain and are often unrecoverable by any means. In my scenario - the funds are still on chain, which means that they are recoverable should there be support from Osmosis validators.
What Happened?
For several weeks I had been encountering what appears to be a UI issue with Mars Protocol. When accessing it via https://mars.osmosis.zone/, then switching to the Neutron outpost, I was unable to view the Mars Farms under the Earn tab which I was considering entering. After some troubleshooting I decided to try an alternative web browser. I chose to use Brave browser, which I never usually use. Against my better judgement, instead of ensuring I used verified links to find the Keplr wallet page, I made the fundamental mistake of searching for “Keplr Wallet” and ended up on the site https://keplrwallet.app/ (which was a sponsored ad at the top of the search page) - which is obviously not the correct site for Keplr wallet. I manually entered my seed phrase after selecting “import an existing wallet” and was then routed to the correct keplr dashboard, unaware of the mistake I’d just made. The phishing scammer then had access to my wallet and subsequently transferred ~$100K of crypto tokens from my wallet, the vast majority of which had been held in Mars Protocol on Osmosis in the form of $91.1K USDC. They also took a small amount of liquid OSMO, they used the liquid staking module to steal my staked ATOM, they took some liquid KUJI & KUJI ecosystem tokens I had & a number of high value NFTs from Stargaze.
4 days later all funds still remain on various Cosmos chains in the attacker’s wallets. With the majority sitting on Osmosis.
They performed 3 key transactions on Osmosis:
-
Removed my USDC from Mars: Mintscan
-
Sent my USDC to their wallet: Mintscan
-
Sent the liquid OSMO from my wallet to theirs: Mintscan
The stolen funds now reside in the wallet with address: osmo120r3lwjh2fn0hu80e0gw5fc0tsk6ce3auvc42p
What can be done?
Given:
- The stolen funds are still on chain
- The size of the stolen funds
- My longstanding community presence within Cosmos
I’m appealing to the Cosmos validators to help either freeze this account and/or return the funds to me.
I realize that this is a big ask given the decentralized an immutable nature of the blockchain. However Osmosis is not the bitcoin network and rather than being controlled by millions of nodes spread across the world, the network is ultimately controlled by 150 validators, and if the majority of those validators chose to take action then this account could be frozen and potentially the transaction could be reversed.
There is some recent precedent for such an action when the validators of both Neutron and Terra froze an address that was responsible for a smart contract hack on the IBC bridge where they were able to mint and extract Axelar wrapped assets on Terra. The wallet was frozen in order to protect Astroport token holders given that 50M ASTRO was minted by the attacker.
My question to you is this: Will you stand idly by and allow a hacker to steal funds on Osmosis, knowing that you can take action to stop it? Will you refuse to act whilst one of your own Cosmos natives is financially ruined by a stupid mistake? Is this really the future of finance, is this the spirit of blockchain technology?
I implore the human side of you to at least consider not allowing this thief to prosper whilst you have the chance to stop them. Whilst I’ve contacted law enforcement in the UK it’s unlikely that they will or can take any steps to either prevent funds moving off chain and in the even that they do it’s highly unlikely that they would be able to track the funds to an individual who is likely based in another jursidiction. I therefore request that justice is brought on chain.
Thank you for your consideration.