/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

After Oasis complied with a UK high court order and upgraded a DeFi contract, Jump recovers ~120,000 ether, worth $140M, stolen during the 2022 Wormhole exploit

There have recently been two high-profile cases … CoinDesk : Oasis Exploits Its Own Wallet Software to Seize Crypto Stolen in Wormhole Hack Born Bored/CK News and Updates News Letter : The Power of NFTs in Art Tweets: @evan_ss6 : So Oasis (@MakerDAO) upgraded a contract to steal the 120,000 ETH back from the Wormhole hacker and return it to Jump Horrendous precedent Chris Blec / @chrisblec : It was only a matter of time. 1) Court orders DeFi project to use multisig to steal money back from hacker 2) DeFi project says “OK!” and uses its multisig to exploit its own code 3) DeFi users are like “oh crap.. what?” What a total joke. https://blog.oasis.app/... https://twitter.com/... Tobias Andersen / @zaradarbh : So crypto was supposed to be inflation proof but every time we get a higher inflation print the price seems to drop 😂 Jump crypto is now actively breaking laws, but TFL is the villain, https://blockworks.co/... 🤦‍♂️ and regulation will turn all our tokens into securities 🥳 Wu Blockchain / @wublockchain : Oasis's response: What occurred on 21st was only possible due to a previously unknown vulnerability in the design of the admin multisig access, with the sole intention to protect user assets in the event of any potential attack. Readmore https://blog.oasis.app/... Christoph Jentzsch / @chrjentzsch : Governance in the hand of a few (MultiSig) and upgradability are a liability. https://twitter.com/... @babaloomagoo : Huge. This should be the biggest news story right now, even if you aren't in DeFi. The implications of this action should be understood by *everyone* If your protocol/DApp/L1 isn't sufficiently decentralized now might be the time to start demanding it. https://twitter.com/... @evan_ss6 : https://blockworks.co/... if they'd do it for Jump, what does that say about possible coercion via state actors? Also just 🤮 re: helping scammers like Jump in any way Ross / @z0r0zzz : This is why I don't use upgradeable contracts. The unknown unknowns of changing code multiply the risks, as seen in how a vault was seized by Oasis admins. https://twitter.com/... https://twitter.com/... Tyler Reynolds / @tbr90 : I'm always surprised that people technical enough to hack DeFi/CeDeFi so frequently seem to ignore centralization risk when parking their ill gotten gains https://twitter.com/... Arthur B. / @arthurb : The entire Polygon network, Arbitrum, Optimism (and the newly launched Base), and virtually all NFTs issued on Solana are all controlled by a small multisig. https://twitter.com/... @ledgerstatus : Is this what immutability looks like? https://twitter.com/... @0xmert_ : seeing a lot of people hate on this nothing sketchy about it — this is a choice you make when interacting with non-frozen programs https://blockworks.co/... Jim / @0xjim : Code is not law. Social coordination that is scaled through code has always been the precedent. Not saying I condone these actions—should open up a lot of conversation on what is “decentralised” https://twitter.com/... @0xngmi : couldn't this happen to all contracts that are upgradeable? https://twitter.com/... @bitfinexed : Coming soon to crypto, whether you like it or not. https://twitter.com/... https://twitter.com/... Matthew Green / @matthew_d_green : The govt just sent a court order to the multisig owners of a smart contract and told them to upgrade the contract. Yikes yikes yikes yikes yikes. https://twitter.com/... Matthew Green / @matthew_d_green : It looks like Jump got their crypto back from the Wormhole hacker, by exploiting a vulnerable DeFi smart contract. https://twitter.com/... Steven / @dogetoshi : “On 21st February 2023, we received an order from the High Court of England and Wales to take all necessary steps that would result in the retrieval of certain assets involved with the wallet address associated with the Wormhole Exploit on the 2nd February 2022.” https://twitter.com/... @krugermacro : Jump Crypto Just Counter-Exploited the Wormhole Hacker for $140 Million Takeaway: avoid upgradeable contracts like the plague unless you want to get hacked https://blockworks.co/... Yano / @jasonyanowitz : Savage move by Jump counter-exploiting the Wormhole hacker for $140 million Big SCOOP by the Blockworks team. https://blockworks.co/...

Blockworks Jon Rice

Context & Ripple Effects

The 2022 Wormhole theft sits in a broader record of exploit proceeds remaining visible on-chain: related coverage tracked Ronin hackers moving funds after that breach. The Jump-Oasis recovery turns that visibility into an enforcement mechanism, because Oasis's contract upgrade was executed under a UK High Court order rather than through an immutable protocol rule.

Related coverage treats the recovery as evidence that multisig control can centralize a DeFi protocol and that upgradeable contracts qualify claims of trustlessness. The immediate return of funds therefore also exposes the governance powers available to Oasis and its users.

First-order effects

  • Jump Crypto regains roughly 120,000 ETH tied to the Wormhole exploit, while Oasis demonstrates that its multisig-controlled contract can be upgraded to comply with a court order.
  • Oasis users and counterparties now have a concrete example of the protocol's administrators altering contract behavior to seize funds from an identified address.

Second-order effects

  • DeFi projects using multisig-controlled, upgradeable contracts face sharper scrutiny from users over who can authorize changes and under what legal circumstances.
  • Hack victims and courts gain a more visible recovery path where stolen assets pass through contracts whose operators retain upgrade authority, rather than relying only on on-chain tracing such as the tracking of Ronin-linked funds.

Third-order effects

  • If court-directed upgrades become a recurring recovery tool, DeFi governance will be judged less by whether code is deployed on-chain than by the legal and operational controls behind its upgrade keys.
  • The case points to a durable divide between protocols designed for immutable execution and services that retain policy intervention powers, with trust shifting toward disclosure of those powers.

The trend: DeFi is moving toward an explicit trade-off between programmable settlement and operator-controlled compliance intervention.

Discussion

  • @evan_ss6 @evan_ss6 on x
    So Oasis (@MakerDAO) upgraded a contract to steal the 120,000 ETH back from the Wormhole hacker and return it to Jump Horrendous precedent
  • @chrisblec Chris Blec on x
    It was only a matter of time. 1) Court orders DeFi project to use multisig to steal money back from hacker 2) DeFi project says “OK!” and uses its multisig to exploit its own code 3) DeFi users are like “oh crap.. what?” What a total joke. https://blog.oasis.app/... https://twitt…
  • @zaradarbh Tobias Andersen on x
    So crypto was supposed to be inflation proof but every time we get a higher inflation print the price seems to drop 😂 Jump crypto is now actively breaking laws, but TFL is the villain, https://blockworks.co/... 🤦‍♂️ and regulation will turn all our tokens into securities 🥳
  • @wublockchain Wu Blockchain on x
    Oasis's response: What occurred on 21st was only possible due to a previously unknown vulnerability in the design of the admin multisig access, with the sole intention to protect user assets in the event of any potential attack. Readmore https://blog.oasis.app/...
  • @chrjentzsch Christoph Jentzsch on x
    Governance in the hand of a few (MultiSig) and upgradability are a liability. https://twitter.com/...
  • @babaloomagoo @babaloomagoo on x
    Huge. This should be the biggest news story right now, even if you aren't in DeFi. The implications of this action should be understood by *everyone* If your protocol/DApp/L1 isn't sufficiently decentralized now might be the time to start demanding it. https://twitter.com/...
  • @z0r0zzz Ross on x
    This is why I don't use upgradeable contracts. The unknown unknowns of changing code multiply the risks, as seen in how a vault was seized by Oasis admins. https://twitter.com/... https://twitter.com/...
  • @tbr90 Tyler Reynolds on x
    I'm always surprised that people technical enough to hack DeFi/CeDeFi so frequently seem to ignore centralization risk when parking their ill gotten gains https://twitter.com/...
  • @evan_ss6 @evan_ss6 on x
    https://blockworks.co/... if they'd do it for Jump, what does that say about possible coercion via state actors? Also just 🤮 re: helping scammers like Jump in any way
  • @arthurb Arthur B. on x
    The entire Polygon network, Arbitrum, Optimism (and the newly launched Base), and virtually all NFTs issued on Solana are all controlled by a small multisig. https://twitter.com/...
  • @ledgerstatus @ledgerstatus on x
    Is this what immutability looks like? https://twitter.com/...
  • @0xmert_ @0xmert_ on x
    seeing a lot of people hate on this nothing sketchy about it — this is a choice you make when interacting with non-frozen programs https://blockworks.co/...
  • @0xjim Jim on x
    Code is not law. Social coordination that is scaled through code has always been the precedent. Not saying I condone these actions—should open up a lot of conversation on what is “decentralised” https://twitter.com/...
  • @0xngmi @0xngmi on x
    couldn't this happen to all contracts that are upgradeable? https://twitter.com/...
  • @bitfinexed @bitfinexed on x
    Coming soon to crypto, whether you like it or not. https://twitter.com/... https://twitter.com/...
  • @matthew_d_green Matthew Green on x
    The govt just sent a court order to the multisig owners of a smart contract and told them to upgrade the contract. Yikes yikes yikes yikes yikes. https://twitter.com/...
  • @matthew_d_green Matthew Green on x
    It looks like Jump got their crypto back from the Wormhole hacker, by exploiting a vulnerable DeFi smart contract. https://twitter.com/...
  • @dogetoshi Steven on x
    “On 21st February 2023, we received an order from the High Court of England and Wales to take all necessary steps that would result in the retrieval of certain assets involved with the wallet address associated with the Wormhole Exploit on the 2nd February 2022.” https://twitter.…
  • @krugermacro @krugermacro on x
    Jump Crypto Just Counter-Exploited the Wormhole Hacker for $140 Million Takeaway: avoid upgradeable contracts like the plague unless you want to get hacked https://blockworks.co/...
  • @jasonyanowitz Yano on x
    Savage move by Jump counter-exploiting the Wormhole hacker for $140 million Big SCOOP by the Blockworks team. https://blockworks.co/...