Hacker Returns Ethereum Domains Lost in Bug Exploit

The ENS hacker returned all 17 domain names after being compensated by OpenSea.

AccessTimeIconOct 4, 2019 at 9:25 p.m. UTC
Updated Aug 18, 2021 at 12:21 p.m. UTC

Presented By Icon

Election 2024 coverage presented by

Stand with crypto

The domain names stolen from the Ethereum Name Service's (ENS) auction have been returned.

As CoinDesk reported at the time, the ENS bidding process managed by digital-collectibles marketplace OpenSea was exploited, allowing a hacker to nab 17 domain names for lower bids than other users placed. ENS and OpenSea asked the hacker to return the domain names, promising compensation for finding the bug.

  • Bitcoin Mining in the U.S. Will Become 'a Lot More Decentralized': Core Scientific CEO
    13:18
    Bitcoin Mining in the U.S. Will Become 'a Lot More Decentralized': Core Scientific CEO
  • Binance to Discontinue Its Nigerian Naira Services After Government Scrutiny
    05:10
    Binance to Discontinue Its Nigerian Naira Services After Government Scrutiny
  • The first video of the year 2024
    04:07
    The first video of the year 2024
  • The last regression video of the year 3.67.0
    40:07
    The last regression video of the year 3.67.0
  • An alternative to Web 2.0’s centralized domain name servers (DNS) system, ENS is built on top of the ethereum blockchain to leverage its immutability and decentralized properties. As it happens, immutability isn't always a good thing.

    Once the hacker claimed the ENS domain names – which included apple.eth – ENS and OpenSea’s only recourse was to blacklist the domains and ask for the hacker to return them.

    Fortunately, they were.

    — OpenSea (@opensea) October 3, 2019

    The hacker was apparently swayed by an attractive offer: 25 percent of the final bidding price for each of the returned domains once they are re-auctioned. Some domain names are listed for impressively high bids such as the owner of coffeshop.eth asking for 100 wrapped ether, worth about $17,000 at press time. With 17 domains stolen, the hacker could be in store for a decent payday depending on the auction prices.

    OpenSea says auctions will commence again in the coming weeks.

    Speaking with CoinDesk, ENS lead developer Nick Johnson said OpenSea had no direct communications with the hacker before the domains were returned. The company solicited feedback in a Sept. 29 blog post disclosing the bug.

    "Evidently the hacker thought 25 percent was a better deal than trying to resell them themselves in the face of blacklisting. Or perhaps they're just generous – either way we're grateful."

    Gift image via Shutterstock

    Disclosure

    Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

    CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.


    Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.



    Read more about