Jump Crypto recovers ~120,000 ether, worth $140M, stolen during the 2022 Wormhole exploit after Oasis upgraded a DeFi contract following a UK high court order
The Chicago trading firm appears to have recovered the 120,000 ether stolen during the 2022 Wormhole exploit.
BlockworksJon Rice
Context & Ripple Effects
The Wormhole breach had already forced its parent company to replace the stolen ETH and resume bridge operations after the attack vector was patched. The subsequent recovery turns part of that loss from an operating backstop into recoverable assets.
Oasis's court-ordered contract upgrade puts the recovery at the center of a DeFi governance dispute: related coverage argues that multisig-controlled upgradeability can override the trustless and censorship-resistant properties users expect.
First-order effects
Jump Crypto recovers roughly 120,000 ETH tied to the Wormhole theft, while Oasis changes a DeFi contract under the UK High Court order to enable that recovery.
Oasis's multisig controllers demonstrate an ability to alter the contract's behavior in response to a legal order, not solely through an on-chain user process.
Second-order effects
Users and counterparties of similarly upgradeable DeFi contracts must account for a new practical recovery path—and an intervention risk—when evaluating who controls protocol upgrades.
Bridge operators and their backers gain a precedent for pursuing stolen assets through courts and contract administrators after exploits, alongside technical patching and balance-sheet replacement.
Third-order effects
If court-directed upgrades become a repeatable recovery mechanism, DeFi's effective governance model shifts toward identifiable multisig operators whose legal exposure can shape contract outcomes.
The divide between immutable protocols and upgradeable, administrator-controlled systems becomes a more consequential design and trust distinction for DeFi users.
The trend: DeFi exploit response is increasingly testing whether upgradeable smart-contract governance functions as decentralized infrastructure or as an administrable recovery layer.
It was only a matter of time. 1) Court orders DeFi project to use multisig to steal money back from hacker 2) DeFi project says “OK!” and uses its multisig to exploit its own code 3) DeFi users are like “oh crap.. what?” What a total joke. https://blog.oasis.app/... https://twitt…
https://blockworks.co/... if they'd do it for Jump, what does that say about possible coercion via state actors? Also just 🤮 re: helping scammers like Jump in any way
I'm always surprised that people technical enough to hack DeFi/CeDeFi so frequently seem to ignore centralization risk when parking their ill gotten gains https://twitter.com/...
The entire Polygon network, Arbitrum, Optimism (and the newly launched Base), and virtually all NFTs issued on Solana are all controlled by a small multisig. https://twitter.com/...
seeing a lot of people hate on this nothing sketchy about it — this is a choice you make when interacting with non-frozen programs https://blockworks.co/...
Code is not law. Social coordination that is scaled through code has always been the precedent. Not saying I condone these actions—should open up a lot of conversation on what is “decentralised” https://twitter.com/...
Jump Crypto Just Counter-Exploited the Wormhole Hacker for $140 Million Takeaway: avoid upgradeable contracts like the plague unless you want to get hacked https://blockworks.co/...
The govt just sent a court order to the multisig owners of a smart contract and told them to upgrade the contract. Yikes yikes yikes yikes yikes. https://twitter.com/...
This is why I don't use upgradeable contracts. The unknown unknowns of changing code multiply the risks, as seen in how a vault was seized by Oasis admins. https://twitter.com/... https://twitter.com/...
“On 21st February 2023, we received an order from the High Court of England and Wales to take all necessary steps that would result in the retrieval of certain assets involved with the wallet address associated with the Wormhole Exploit on the 2nd February 2022.” https://twitter.…