Security Incident Post-Mortem Report — and The Road Ahead
2023-11-18 • Uno Re •
https://medium.com/@LunosDAO/security-incident-post-mortem-report-and-the-road-ahead-acb38aaf3f11
A compromised Uno Re deployer private key let an attacker transfer contract ownership, alter the claims assessor role, and drain SSIP, SSRP, and Rewarder contracts. Uno Re reported losses of 32.4 million UNO, 127.9 thousand USDC, 59.3 thousand USDT, and 18.4 ETH, with stolen UNO sold through Uniswap and PancakeSwap before proceeds were moved through exchanges, mixers, swaps, and additional chains. Forensic work suggested the attack may be part of a broader operation targeting developer and deployer accounts, with DareNFT and LunaFi cited as related examples, but the report did not attribute the activity to a named threat actor. Uno Re planned multisig, contract-permission, monitoring, decentralization, audit, and bug-bounty changes while pursuing fund recovery and LP compensation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://etherscan.io/tx/0x0acda… | 2023-11-18 | 2023-11-18 |
| URL | https://etherscan.io/tx/0x2af32… | 2023-11-18 | 2023-11-18 |
| URL | https://bscscan.com/tx/0xcf1254… | 2023-11-18 | 2023-11-18 |
| WALLET | 0xb782425e27a88921189a05be71997… | 2023-11-18 | 2023-11-18 |
| URL | https://etherscan.io/tx/0x7f871… | 2023-11-18 | 2023-11-18 |
| URL | https://etherscan.io/tx/0xad359… | 2023-11-18 | 2023-11-18 |
| WALLET | 0x9ada20B835Aa178813A8C174F1F93… | 2023-11-18 | 2023-11-18 |