Crypto Startup Hacks Itself to Save $13 Million in Users’ Cryptocurrency

The startup says the users can reclaim their funds.

Advertisement
By Gaurav Shukla | Updated: 7 June 2019 14:33 IST
Highlights
  • Komodo transferred over $13 million worth of crypto to its own wallets
  • Komodo was informed about the vulnerability on Wednesday
  • The startup hacked its own wallets the same day

Agama wallet of Komodo blockchain platform was found to be housing a vulnerability

Photo Credit: Komodo

In an interesting tale of quick thinking, a cryptocurrency startup claims to have hacked its own customers to save their funds from a malicious third-party. Apparently, Komodo, which is a crypto-platform, discovered a vulnerability in its Agama Wallet, which potentially put funds of several Agama users at risk. In order to save these funds from hackers, for whom the impacted wallets would have been easy-pickings, Komodo used the same vulnerability to hack the user wallets and save as much as 8 million Komodos or KMD (which is roughly $12.48 million or Rs. 86.6 crores) and 96 Bitcoins or BTC (which is roughly $765,000 or Rs. 5.3 crores).

As per a blog post on Komodo's official website, the blockchain platform on Wednesday was informed about an issue with one of the libraries used by the Agama wallet. This issue had potentially put the consumers using the Agama wallet to store their cryptocurrencies at risk. Without waiting to make and release a patch and then hoping for the customers to apply it, the Komodo team decided to hack the wallets themselves before someone else can and transfer all the cryptocurrency to themselves in an effort to save it.

Advertisement

Komodo says the collected funds are present in RSgD2cmm3niFRu2kwwtrEHoHMywJdkbkeF (KMD) and 1GsdquSqABxP2i7ghUjAXdtdujHjVYLgqk (BTC) wallets and can be reclaimed by their owners. The consumer whose funds have been transferred to the company can use this form to reclaim them.

According to Komodo, all Agama Wallets downloaded from its website, Atomic explorer wallet, and Agama Mobile wallets are affected by the vulnerability. The Verus Agama, KomodoOcean QT, and Ledger Hardware wallet are not impacted.

Advertisement

Although the Komodo blog post doesn't include any technical details of the vulnerability, npn package manager's team has shared some information. npn's service was used to push a malicious dependency to Agama wallet.

“The attack was carried out by using a pattern that is becoming more and more popular; publishing a “useful” package (electron-native-notify) to npm, waiting until it was in use by the target, and then updating it to include a malicious payload,” npm team wrote in a blog post.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Komodo, Agama Wallet
Advertisement
Popular Mobile Brands
  1. Why The iPhone 18 Pro Series Might Feature a Larger Camera Module
  2. Boat Launches Airdopes ProClip With Up to 52-Hour Battery Life: See Price
  3. GTA 6 Price, Pre-Order Details and Editions Announced; $80 Price Confirmed
  4. Infinix Note 60 Pro Pininfarina Edition Debuts in India at This Price
  1. WhatsApp Starts Warning Users About Chats From Unknown Numbers
  2. OpenPayd Secures MiCA Licence as Stablecoins Gain Traction Across Europe
  3. iPhone 18 Pro, iPhone 18 Pro Max Camera Upgrades Said to Result in Thicker Rear Camera Module, Larger Lenses
  4. Grand Theft Auto 6 Price, Editions Revealed; Pre-Orders Begin at Midnight on June 25
  5. Amazon Plans to Expand Quick Commerce Service to 300 Cities in India, Unveils Welfare Programme for Associates
  6. Infinix Note 60 Pro Pininfarina Edition Launched in India With 6,500mAh Battery, Snapdragon 7s Gen 4 SoC
  7. Sony Bravia Theatre Trio Launched in India Alongside Bravia Theatre Bar 7, Bar 5 and New Wireless Speakers, Subwoofers
  8. THORChain Resumes Operations Weeks After $10 Million Exploit
  9. Boat Airdopes ProClip Launched in India With 12mm Drivers, Up to 52 Hours Total Playback Time: Price, Features
  10. Mark Zuckerberg Directed Meta to Create a Prediction Markets App: Report
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.