/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The recovery of ~120K stolen ether by Jump and Oasis demonstrates the centralization of DeFi enabled by multisig-controlled upgradable smart contracts

Wormhole, Jump Crypto, and Oasis demonstrate the centralization threat introduced by multisig-controlled upgradable smart contracts.

Molly White

Context & Ripple Effects

The recovery followed Oasis's compliance with a UK High Court order and a contract upgrade, allowing Jump to reclaim ether taken in the Wormhole exploit. It turns an earlier wave of bridge hacks into a governance test: the same intervention capability that can remedy a theft also places control with a multisig and, here, a court-backed process.

First-order effects

  • Jump Crypto recovers roughly 120,000 ether from the Wormhole theft after Oasis alters the relevant DeFi contract under the court order.
  • Oasis's multisig administrators demonstrate that they can change contract behavior and act on a legal directive, rather than leaving execution solely to immutable code.

Second-order effects

  • Bridge and DeFi users must evaluate administrator and legal-intervention risk alongside exploit risk, particularly after the Oasis contract upgrade enabled the recovery.
  • Other protocols using multisig-controlled upgrades face a sharper trade-off: retaining an emergency recovery mechanism makes them more responsive to thefts but weakens claims of censorship resistance.

Third-order effects

  • If court-directed contract upgrades become an accepted recovery path, DeFi governance will look less like autonomous settlement and more like software infrastructure with identifiable control points.
  • The pattern deepens the sector's legitimacy challenge: security remediation and user recourse may depend on the same centralized powers that trustless systems were designed to reduce.

The trend: DeFi is converging on a model in which upgrade authorities and legal orders can override nominally autonomous smart-contract execution.

Discussion

  • @danyork@mastodon.social Dan York on mastodon
    Another fascinating and brilliant post from @molly0xfff about the reality of #centralization within “DeFi” and how for convenience, immutable actions have become mutable.  A key quote for me: …
  • @molly0xfff Molly White on x
    Grab your machete because we're getting into the weeds. The “counter-hack” by Jump Crypto and Oasis just provided a remarkable demonstration of the centralization of defi. Read more: https://newsletter.mollywhite.net/ ...
  • @molly0xfff Molly White on x
    I run into this a lot in crypto. People decide to use a blockchain and incur huge speed/$/scalability costs, then themselves undermine all the things the blockchain is supposed to do, ending up with a version of existing products that's just slow, expensive, and doesn't scale. ht…
  • @blockworksres @blockworksres on x
    2/ We published a free report on Blockworks Research that details exactly how the counter exploit was facilitated. This report includes links to all addresses and transactions mentioned below. The rest of this thread hits the highlights 👇 https://www.blockworksresearch.com/ ...
  • @tayvano_ Tay on x
    Here's the key pieces about the actions with regards to the “sender” (aka Jump) and the “multisig” (aka Oasis) https://www.blockworksresearch.com/ ... https://twitter.com/...
  • @tayvano_ Tay on x
    It looks like in both these cases the contracts were upgraded / funds moved by the parties from whom the funds were originally stolen from. It was almost certainly Jump + Whitehats who actually did the thing This post by @smyyguy is fantastic https://www.blockworksresearch.com/ .…
  • @tayvano_ Tay on x
    And here's the key pieces about the system design that allowed the Oasis 4-of-12 multisig to be used to be able to take action on behalf of an independent entity's vault https://www.blockworksresearch.com/ ... https://twitter.com/...
  • @evan_ss6 @evan_ss6 on x
    So Oasis (@MakerDAO) upgraded a contract to steal the 120,000 ETH back from the Wormhole hacker and return it to Jump Horrendous precedent
  • @chrisblec Chris Blec on x
    It was only a matter of time. 1) Court orders DeFi project to use multisig to steal money back from hacker 2) DeFi project says “OK!” and uses its multisig to exploit its own code 3) DeFi users are like “oh crap.. what?” What a total joke. https://blog.oasis.app/... https://twitt…
  • @zaradarbh Tobias Andersen on x
    So crypto was supposed to be inflation proof but every time we get a higher inflation print the price seems to drop 😂 Jump crypto is now actively breaking laws, but TFL is the villain, https://blockworks.co/... 🤦‍♂️ and regulation will turn all our tokens into securities 🥳
  • @wublockchain Wu Blockchain on x
    Oasis's response: What occurred on 21st was only possible due to a previously unknown vulnerability in the design of the admin multisig access, with the sole intention to protect user assets in the event of any potential attack. Readmore https://blog.oasis.app/...
  • @chrjentzsch Christoph Jentzsch on x
    Governance in the hand of a few (MultiSig) and upgradability are a liability. https://twitter.com/...
  • @babaloomagoo @babaloomagoo on x
    Huge. This should be the biggest news story right now, even if you aren't in DeFi. The implications of this action should be understood by *everyone* If your protocol/DApp/L1 isn't sufficiently decentralized now might be the time to start demanding it. https://twitter.com/...
  • @z0r0zzz Ross on x
    This is why I don't use upgradeable contracts. The unknown unknowns of changing code multiply the risks, as seen in how a vault was seized by Oasis admins. https://twitter.com/... https://twitter.com/...
  • @tbr90 Tyler Reynolds on x
    I'm always surprised that people technical enough to hack DeFi/CeDeFi so frequently seem to ignore centralization risk when parking their ill gotten gains https://twitter.com/...
  • @evan_ss6 @evan_ss6 on x
    https://blockworks.co/... if they'd do it for Jump, what does that say about possible coercion via state actors? Also just 🤮 re: helping scammers like Jump in any way
  • @arthurb Arthur B. on x
    The entire Polygon network, Arbitrum, Optimism (and the newly launched Base), and virtually all NFTs issued on Solana are all controlled by a small multisig. https://twitter.com/...
  • @ledgerstatus @ledgerstatus on x
    Is this what immutability looks like? https://twitter.com/...
  • @0xmert_ @0xmert_ on x
    seeing a lot of people hate on this nothing sketchy about it — this is a choice you make when interacting with non-frozen programs https://blockworks.co/...
  • @0xjim Jim on x
    Code is not law. Social coordination that is scaled through code has always been the precedent. Not saying I condone these actions—should open up a lot of conversation on what is “decentralised” https://twitter.com/...
  • @0xngmi @0xngmi on x
    couldn't this happen to all contracts that are upgradeable? https://twitter.com/...
  • @bitfinexed @bitfinexed on x
    Coming soon to crypto, whether you like it or not. https://twitter.com/... https://twitter.com/...
  • @matthew_d_green Matthew Green on x
    The govt just sent a court order to the multisig owners of a smart contract and told them to upgrade the contract. Yikes yikes yikes yikes yikes. https://twitter.com/...
  • @matthew_d_green Matthew Green on x
    It looks like Jump got their crypto back from the Wormhole hacker, by exploiting a vulnerable DeFi smart contract. https://twitter.com/...
  • @dogetoshi Steven on x
    “On 21st February 2023, we received an order from the High Court of England and Wales to take all necessary steps that would result in the retrieval of certain assets involved with the wallet address associated with the Wormhole Exploit on the 2nd February 2022.” https://twitter.…
  • @krugermacro @krugermacro on x
    Jump Crypto Just Counter-Exploited the Wormhole Hacker for $140 Million Takeaway: avoid upgradeable contracts like the plague unless you want to get hacked https://blockworks.co/...
  • @jasonyanowitz Yano on x
    Savage move by Jump counter-exploiting the Wormhole hacker for $140 million Big SCOOP by the Blockworks team. https://blockworks.co/...