URGENT: Suspected Bifrost Farming/vDOT exploit — please escalate to the security team

13hrs 58mins ago
0

URGENT: Suspected Bifrost Farming/vDOT exploit — please escalate to the security team

Exploit transaction:
hxxps://bifrost.subscan.io/extrinsic/13362457-2

Suspected attacker wallet:
14YaJGZfaX5dt1zGLennQ1NKyfiRC6KBoCkaJ3ASdKNvqJqD

An EVM contract repeatedly interacted with Farming pid 0 and claimed excessive rewards.

The contract initially received 16 vDOT:
hxxps://bifrost.subscan.io/event/13362457-12

It later transferred 562,278.4782975528 vDOT back to the suspected attacker:
hxxps://bifrost.subscan.io/event/13362457-397

After subtracting the initial 16 vDOT, approximately 562,262.4783 vDOT appears to have originated from the Farming keeper.

Farming keeper:
13UVJyLjmw1yiNjb6qFE3b5ZJDkQjfQpznH9NnfV3QXLdEF1

Keeper page:
hxxps://bifrost.subscan.io/account/13UVJyLjmw1yiNjb6qFE3b5ZJDkQjfQpznH9NnfV3QXLdEF1

Estimated keeper balance before incident: ~562,426.5 vDOT
Current keeper balance: ~164.007 vDOT

The suspected attacker then swapped 562,280.5476 vDOT for 881,150.1956 DOT:
hxxps://bifrost.subscan.io/extrinsic/13362465-2

The DOT-vDOT pool price has largely recovered through arbitrage, but price recovery does not prove the Farming vulnerability is fixed.

Please urgently confirm:

  1. Has Farming pid 0 or the affected EVM/precompile path been disabled?
  2. Has the reward-claim vulnerability been patched?
  3. Is automatic refilling of the Farming keeper stopped?
  4. Can another wallet repeat this against other Farming pools?
  5. Is vDOT still fully backed and redeemable?
  6. Will Bifrost publish an official incident report and recovery plan?

Please provide an official transaction, runtime upgrade, governance action, or technical explanation confirming mitigation.

Reply
Up
Share
Comments