The recovery of ~120K stolen ether by Jump and Oasis demonstrates the centralization of DeFi enabled by multisig-controlled upgradable smart contracts
Wormhole, Jump Crypto, and Oasis demonstrate the centralization threat introduced by multisig-controlled upgradable smart contracts.
Molly White
Context & Ripple Effects
The recovery followed Oasis's compliance with a UK High Court order and a contract upgrade, allowing Jump to reclaim ether taken in the Wormhole exploit. It turns an earlier wave of bridge hacks into a governance test: the same intervention capability that can remedy a theft also places control with a multisig and, here, a court-backed process.
First-order effects
- Jump Crypto recovers roughly 120,000 ether from the Wormhole theft after Oasis alters the relevant DeFi contract under the court order.
- Oasis's multisig administrators demonstrate that they can change contract behavior and act on a legal directive, rather than leaving execution solely to immutable code.
Second-order effects
- Bridge and DeFi users must evaluate administrator and legal-intervention risk alongside exploit risk, particularly after the Oasis contract upgrade enabled the recovery.
- Other protocols using multisig-controlled upgrades face a sharper trade-off: retaining an emergency recovery mechanism makes them more responsive to thefts but weakens claims of censorship resistance.
Third-order effects
- If court-directed contract upgrades become an accepted recovery path, DeFi governance will look less like autonomous settlement and more like software infrastructure with identifiable control points.
- The pattern deepens the sector's legitimacy challenge: security remediation and user recourse may depend on the same centralized powers that trustless systems were designed to reduce.
The trend: DeFi is converging on a model in which upgrade authorities and legal orders can override nominally autonomous smart-contract execution.
Related: Programmable settlement versus policy control · Crypto legitimacy gap · Jump Crypto · Oasis contract upgrade enabled ether recovery · Bridge hacks expose security weaknesses
Related Coverage
- Two Prime Embraces Crypto Trend-Following Strategy Blockworks · Michael Bodley
- Solana tries turning it off and on again (twice) Web3 is Going Just Great · Molly White
- Jump crypto & Oasis successfully reclaim over $225 Million Stolen in Wormhole Hack Cryptopolitan · Lacton Muriuki
- Statement Regarding The Transactions From The Oasis Multisig on 21st Feb 2023 Oasis Blog · Chris
- Wormhole Bridge Exploit: $140M Worth Stolen Assets Recovered CryptoPotato · Chayanika Deka
- Four top cryptocurrency stories from the past week The Block · Vishal Chawla
- Jump Crypto and Oasis recover 120k ETH from Wormhole exploit crypto.news · Samuel Mbaki Wanjiku
- Jump Crypto Trading Firm Strikes Back: Recovers $140 Million Stolen Crypto from Wormhole Hack - Here's What Happened Cryptonews · Ruholamin Haqshanas
- Jump crypto & Oasis recover over $225 million stolen in Wormhole hack via court authorized counter-exploit DataBreaches.net
- How These Whitehat Hackers Helped Oasis Network Get Back $140 Million In Stolen Crypto Bitcoinist.com · Christian Encila
- Jump Crypto and Oasis.app ‘counter exploits’ Wormhole hacker for $225M Cointelegraph · Brian Quarmby
- Oasis recovered $140m of stolen Wormhole funds with help of whitehat hackers CryptoSlate · Mike Dalton
- Call an ambulance, but not for me — There have recently been two high-profile cases … BowTiedPickle's Pickle Jar
- Oasis Exploits Its Own Wallet Software to Seize Crypto Stolen in Wormhole Hack CoinDesk
Discussion
-
@danyork@mastodon.social
Dan York
on mastodon
Another fascinating and brilliant post from @molly0xfff about the reality of #centralization within “DeFi” and how for convenience, immutable actions have become mutable. A key quote for me: …
-
@molly0xfff
Molly White
on x
Grab your machete because we're getting into the weeds. The “counter-hack” by Jump Crypto and Oasis just provided a remarkable demonstration of the centralization of defi. Read more: https://newsletter.mollywhite.net/ ...
-
@molly0xfff
Molly White
on x
I run into this a lot in crypto. People decide to use a blockchain and incur huge speed/$/scalability costs, then themselves undermine all the things the blockchain is supposed to do, ending up with a version of existing products that's just slow, expensive, and doesn't scale. ht…
-
@blockworksres
@blockworksres
on x
2/ We published a free report on Blockworks Research that details exactly how the counter exploit was facilitated. This report includes links to all addresses and transactions mentioned below. The rest of this thread hits the highlights 👇 https://www.blockworksresearch.com/ ...
-
@tayvano_
Tay
on x
Here's the key pieces about the actions with regards to the “sender” (aka Jump) and the “multisig” (aka Oasis) https://www.blockworksresearch.com/ ... https://twitter.com/...
-
@tayvano_
Tay
on x
It looks like in both these cases the contracts were upgraded / funds moved by the parties from whom the funds were originally stolen from. It was almost certainly Jump + Whitehats who actually did the thing This post by @smyyguy is fantastic https://www.blockworksresearch.com/ .…
-
@tayvano_
Tay
on x
And here's the key pieces about the system design that allowed the Oasis 4-of-12 multisig to be used to be able to take action on behalf of an independent entity's vault https://www.blockworksresearch.com/ ... https://twitter.com/...
-
@evan_ss6
@evan_ss6
on x
So Oasis (@MakerDAO) upgraded a contract to steal the 120,000 ETH back from the Wormhole hacker and return it to Jump Horrendous precedent
-
@chrisblec
Chris Blec
on x
It was only a matter of time. 1) Court orders DeFi project to use multisig to steal money back from hacker 2) DeFi project says “OK!” and uses its multisig to exploit its own code 3) DeFi users are like “oh crap.. what?” What a total joke. https://blog.oasis.app/... https://twitt…
-
@zaradarbh
Tobias Andersen
on x
So crypto was supposed to be inflation proof but every time we get a higher inflation print the price seems to drop 😂 Jump crypto is now actively breaking laws, but TFL is the villain, https://blockworks.co/... 🤦♂️ and regulation will turn all our tokens into securities 🥳
-
@wublockchain
Wu Blockchain
on x
Oasis's response: What occurred on 21st was only possible due to a previously unknown vulnerability in the design of the admin multisig access, with the sole intention to protect user assets in the event of any potential attack. Readmore https://blog.oasis.app/...
-
@chrjentzsch
Christoph Jentzsch
on x
Governance in the hand of a few (MultiSig) and upgradability are a liability. https://twitter.com/...
-
@babaloomagoo
@babaloomagoo
on x
Huge. This should be the biggest news story right now, even if you aren't in DeFi. The implications of this action should be understood by *everyone* If your protocol/DApp/L1 isn't sufficiently decentralized now might be the time to start demanding it. https://twitter.com/...
-
@z0r0zzz
Ross
on x
This is why I don't use upgradeable contracts. The unknown unknowns of changing code multiply the risks, as seen in how a vault was seized by Oasis admins. https://twitter.com/... https://twitter.com/...
-
@tbr90
Tyler Reynolds
on x
I'm always surprised that people technical enough to hack DeFi/CeDeFi so frequently seem to ignore centralization risk when parking their ill gotten gains https://twitter.com/...
-
@evan_ss6
@evan_ss6
on x
https://blockworks.co/... if they'd do it for Jump, what does that say about possible coercion via state actors? Also just 🤮 re: helping scammers like Jump in any way
-
@arthurb
Arthur B.
on x
The entire Polygon network, Arbitrum, Optimism (and the newly launched Base), and virtually all NFTs issued on Solana are all controlled by a small multisig. https://twitter.com/...
-
@ledgerstatus
@ledgerstatus
on x
Is this what immutability looks like? https://twitter.com/...
-
@0xmert_
@0xmert_
on x
seeing a lot of people hate on this nothing sketchy about it — this is a choice you make when interacting with non-frozen programs https://blockworks.co/...
-
@0xjim
Jim
on x
Code is not law. Social coordination that is scaled through code has always been the precedent. Not saying I condone these actions—should open up a lot of conversation on what is “decentralised” https://twitter.com/...
-
@0xngmi
@0xngmi
on x
couldn't this happen to all contracts that are upgradeable? https://twitter.com/...
-
@bitfinexed
@bitfinexed
on x
Coming soon to crypto, whether you like it or not. https://twitter.com/... https://twitter.com/...
-
@matthew_d_green
Matthew Green
on x
The govt just sent a court order to the multisig owners of a smart contract and told them to upgrade the contract. Yikes yikes yikes yikes yikes. https://twitter.com/...
-
@matthew_d_green
Matthew Green
on x
It looks like Jump got their crypto back from the Wormhole hacker, by exploiting a vulnerable DeFi smart contract. https://twitter.com/...
-
@dogetoshi
Steven
on x
“On 21st February 2023, we received an order from the High Court of England and Wales to take all necessary steps that would result in the retrieval of certain assets involved with the wallet address associated with the Wormhole Exploit on the 2nd February 2022.” https://twitter.…
-
@krugermacro
@krugermacro
on x
Jump Crypto Just Counter-Exploited the Wormhole Hacker for $140 Million Takeaway: avoid upgradeable contracts like the plague unless you want to get hacked https://blockworks.co/...
-
@jasonyanowitz
Yano
on x
Savage move by Jump counter-exploiting the Wormhole hacker for $140 million Big SCOOP by the Blockworks team. https://blockworks.co/...