Optimism exploiter sends 1 million OP tokens to Vitalik Buterin's wallet

Quick Take

  • The attacker stole 20 million OP tokens from crypto market maker outfit Wintermute.
  • They sent 1 million tokens to Vitalik Buterin’s wallet and delegated the token’s voting rights to Ethereum Foundation security researcher Yoav Weiss.

The attacker who sniped 20 million Optimism (OP) tokens meant for crypto market maker Wintermute has sent 1 million of those coins to Ethereum co-founder Vitalik Buterin’s wallet address, according to PeckShield.

Data from Etherscan shows the transfer occurred at 12:26 AM UTC with the attacker sending tokens worth about $874,000. It is unclear why they sent the tokens to Buterin's wallet having previously sold a large chunk of them. One element may be that the tokens are largely illiquid on decentralized exchanges, since there is very little liquidity left, and so can't be sold for much at present.

The exploiter also delegated voting rights for the 1 million tokens to Ethereum Foundation security researcher Yoav Weiss. Buterin had also previously delegated his 1,746 OP tokens from the Optimism airdrop to Weiss as well. Weiss has tweeted that he is not the hacker but suggested that the person might be a white hat hacker.

The attack happened due to a mistake made by Wintermute. The crypto market maker secured a 20 million OP token grant from Optimism but provided a multi-signature Ethereum address that was yet to be deployed on the Optimism network.


Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

This error allowed the hacker to claim the undeployed address on Optimism thereby siphoning all the funds. Wintermute says it bought the 1 million tokens immediately sold by the attacker following the exploit.

Wintermute has asked the hacker to return the stolen OP tokens while offering a consulting role to the entity responsible. The exploiter has one week to respond to Wintermute’s offer but — having sent this further amount to Buterin — now only 18 million of the stolen 20 million are left in their wallet.

© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Author

Osato is a news reporter at The Block as part of the crypto ecosystems team that focuses on DAO governance, staking, blockchain layers, and DeFi. He was previously a news reporter at Cointelegraph. Based in Lagos, Nigeria, he enjoys crosswords, poker, and attempting to beat his Scrabble high score. Follow him on Twitter at @OsatoNomayo.