Jump vs Oasis backstory revealed: English court ordered Oasis code exploit


0 recorded changes
Want your article here?
Promote with Leviathan News

0 recorded changes
Want your article here?
Promote with Leviathan NewsThe story concerns a February 2023 “reverse exploit” in which Jump Crypto, working with DeFi front-end and vault manager Oasis.app, used a smart contract upgrade path—under direction from the High Court of England and Wales—to seize assets from the wallet of the 2022 Wormhole bridge exploiter. In February 2022, the Wormhole bridge had been hacked for about 120,000 ETH (roughly $320–325 million at the time), with Jump, Wormhole’s backer, stepping in to backstop user losses. Roughly a year later, an external white-hat group disclosed to Oasis a vulnerability in its upgradeable vault infrastructure that, if used with Oasis’ cooperation, could move the exploiter’s collateral from their Oasis-managed Maker vaults. According to Oasis’ public statement and subsequent on‑chain analysis, Oasis received an order from the High Court of England and Wales on 21 February 2023 requiring it to take “all necessary steps” to retrieve assets linked to the Wormhole exploiter’s Oasis vaults. Using its multisig upgrade authority and a specially prepared contract path, Oasis executed a sequence of upgrades and calls that migrated the exploiter’s Maker vault positions to a new vault controlled by a court‑authorized third party, repaid the DAI debt, and then withdrew the underlying collateral. Around $140–150 million in assets (mainly wstETH/rETH collateral corresponding to the original stolen ETH) were recovered and transferred to a wallet controlled by that third party, widely understood to be associated with Jump. The revelation that the counter‑exploit depended on Oasis’ ability to unilaterally change vault logic and redirect user funds – albeit only when compelled by a court and coordinated with its multisig – sparked a broader debate about centralization and trust assumptions in DeFi. Analysts highlighted how multisig‑controlled, upgradeable smart contracts can be used not only to patch bugs but also to override user expectations of immutable control, especially when legal orders are involved. Oasis said it would patch the vulnerability that enabled the maneuver and emphasized that, outside of court‑ordered interventions with multisig consent, third parties could not independently drain user vaults.
AI-generated background, compiled from web sources — not editorial content.

The Block ·

𝕏/@bobbyong ·

𝕏/@TheBlockCo ·

Coindesk ·

ꘜ/@defimon_alerts ·

𝕏/@blockaid_ ·

The Block ·

𝕏/@bobbyong ·

𝕏/@TheBlockCo ·

Coindesk ·

ꘜ/@defimon_alerts ·

𝕏/@blockaid_ ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?