Sonic DEX Hack: Technical Report, Asset Tracing, compensation plan and future plans

Alright everyone together now!

:musical_note:

You gotta hack a contract or.. twooooooo!

No, you know I accidentally voted yes on it. Stop trying to push fake narratives.

Weird how you don’t get banned for this. I guess we were right about you guys working for somebody in the foundation. Oh well, won’t matter soon, Toko’s going to launch. Cya, losers.

Weird how you don’t get banned for constantly creating alts and creating conspiracy theories.

Must be working for someone with contacts in the foundation. Toko has been close to launching for 3 years now. Stop the false hope

We only had the idea for Toko last spring lol. Have you not checked out all the different repos we’ve launched?

Dear Community,

Sonic User Fund Recovery Portal Is Now Live!
Following the recent Sonic DEX exploit, we have launched a dedicated User Fund Recovery Portal for community members whose liquidity was affected by the incident.

The portal allows eligible users to connect the ICP wallet they used to provide liquidity and verify their positions based on our pre-drain snapshot of Sonic LP holders.

How it works

  • Connect the wallet you used to provide liquidity on Sonic DEX.
  • Your wallet principal is matched against our pre-drain LP snapshot.
  • Your affected liquidity positions will be displayed for verification.
  • Submit your claim through the portal for review and recovery.

Safe & Read-Only

Connecting your wallet to the portal is read-only. It does not request transaction signatures, approvals, or access to move your funds.

Supported Wallets

Plug • Internet Identity • NFID • OISY • Bitfinity • Stoic • AstroX • MSQ

Important

This recovery portal is exclusively for affected user funds.

Our team will verify submitted claims against the pre-drain on-chain records and process eligible recoveries according to the recovery program.

We understand the importance of getting affected users through this process as smoothly as possible and will continue to provide updates as the recovery program progresses.

:backhand_index_pointing_right: Recovery Portal: Login to sonic dex

https://app.sonic.ooo/claim/ (since you used a new account that is not allowed to post links).

Sneed DAO held an LP position that was drained under it’s governance principal: fi3zi-fyaaa-aaaaq-aachq-cai

While the drain was ongoing we transferred the position to a DAO controlled canister where we could rapidly withdraw the funds with fewer proposals (ok64y-uiaaa-aaaag-qdcbq-cai). However, by the time the proposals to transfer the position passed, the malicious actor had finished draining the pool.

Since we cannot sign into the claim portal with either of these identities, how would you recommend we submit a claim?

As of now we are considering normal user funds. We mentioned it in the post aswell

A user is an entity that uses your service. Whether that entity is a human logging into your UI or a DAO who provided funds from their treasury on behalf of a group of humans sitting behind their computer is a fairly arbitrary bar. The only difference is that DAO’s are probably your largest users who provided the most funds, and so by making the distinction you can claim to be refunding your “users” without actually having to provide any substantial amount of funds.

Also, can you respond to @Snassy-icp 's inquiry made at the beginning of this thread: https://forum.dfinity.org/t/sonic-dex-hack-technical-report-asset-tracing-compensation-plan-and-future-plans/74883/2

This is a legitimate question and could prove to be quite insightful depending on the answers.