Hacker returns stolen funds to Tender.fi, gets $97K bounty reward

The hacker behind the exploit on decentralized finance lending platform Tender.fi has returned the stolen funds for a reward of $97,000 in Ether (ETH).

The exploit was executed at 10:28am UTC on March 7, and Tender.fi confirmed the incident on Twitter soon after, citing "an unusual amount of lending" and adding that it had stopped all lending.

Blockchain data showed that the exploiter used a flaw in the price oracle to borrow $1.59 million in assets from the protocol by depositing 1 GMX token, valued at around $71.

โ€œIt seems your oracle was misconfigured. contact me to resolve thisโ€, the hacker wrote in a chain message.

Message sent to Tender.fi from the price oracle exploiter. Source: arbiscano

Eight hours later, the DeFi protocol announced that it had reached an agreement with the exploiter "White Hat", in which the hacker would repay all loans except a "reward" of 62.16 ETH, worth around $ 97,000 at current prices.

Another hour later, Tender.fi confirmed on Twitter that the exploiter had completed the loan payments.

โ€œFunds are officially SaFu, postmortem on the way,โ€ he wrote.

Related: DeFi Lender Tender.fi Suffers Exploit, White Hat Hacker Suspected

In August last year, the cross-chain Nomad Bridge appealed to exploiters who participated in a smart contract exploit that drew $190 million in funds from the bridge in less than three hours.

Within hours, approximately $32.6 million in funds they were already returnedsuggesting that some of the exploiters may have been white hat hackers attempting to extract funds for later safe return.

Later in the month, non-fungible token firm Metagame even offered a "Whitehat Award." in the form of NFTs for anyone who could prove they returned at least 90% of the funds they stole from the protocol.

Blockchain data of Nomad's official fund recovery address shows that the funds continued to be returned to the recovery address since then, with the last transaction Recorded on February 18 for $7,868 in Covalent Query Token (CQT).