Decentralized Exchanges' Achilles Heel: Who Holds the Keys?
Two decentralized perpetuals exchanges on Arbitrum were emptied in July, resulting in losses of around $42 million. The attacks took place within eight days, with Ostium being compromised on July 15 and AFX Trade on July 22.
The entry point for both attackers was not a smart contract but a private key held by individuals. This highlights the central marketing promise of decentralization, which implies that nobody can take users' money because nobody holds it. However, in many cases, deposits are stored behind bridges whose signing keys are kept on servers unknown to users.
The two incidents involved compromising private keys related to price oracles and validator signing keys for USDC custody bridges. In both cases, the attackers were able to withdraw large sums of money from the exchanges.