untitled design

PeopleDAO swindled $120,000 in ETH using a Google spreadsheet

On March 6, the PeopleDAO community, created to acquire a rare copy of the US Constitution, was hacked. The damage amounted to 76.5 ETH ($120,000).

As it became known, PeopleDAO’s accounting department mistakenly posted a link to a Google spreadsheet with a monthly payment form on a public Discord channel. The document has edit permissions. The unknown person entered the address of his wallet and the amount of payment in the amount of 76.5 ETH into it, after which he made this line invisible.

“Teamleads did not find the hidden line when rechecking. The data file from the table was then sent to the CSV Airdrop tool on the Safe platform for reward distribution. The validators also did not notice the malicious transfer,” explained the PeopleDAO team.

Subsequently, the hacker transferred 69.2 ETH to the HitBTC exchange and 7.3 ETH to Binance. Both trading platforms along with law enforcement have been notified of the incident.

PeopleDAO is also conducting an internal investigation with blockchain security experts ZachXBT and SlowMist. The community offered the hacker a cashback reward of 10% of the stolen amount. At the time of writing, he has not responded to the offer.

Separately, the team will improve accounting and train validators to work with multi-signatures.


Source: Cryptocurrency

You may also like

Get the latest

Stay Informed: Get the Latest Updates and Insights

 

Most popular