Aethir bridge exploit drains funds due to missing onlyOwner modifier on transferOwnership; attacker bridges ~$90K to Tron as Binance attempts to freeze remaining assets.
Security & Exploits ·
Aethir detected a bridge exploit affecting its ATH token contracts across multiple chains and moved to contain the damage. The attack stemmed from a missing onlyOwner modifier on a transferOwnership() function, allowing an attacker to drain approximately $90,000 in user funds. The compromised contracts have been disconnected, and Aethir reports that the main ATH supply on Ethereum and the ETH-ARB bridge on Squid remain unaffected.
The attacker moved stolen funds to Tron while Aethir engaged exchanges to freeze tracked wallets. Binance, Upbit, Bithumb, HTX and other partners rapidly blacklisted wallets connected to the exploit. Specific compromised contract addresses were identified across Ethereum, Solana, zkSync, Sophon and Beam chains. Zeroshadow_io provided analysis support during the response.
Aethir committed to releasing a full compensation plan the following week and stated it would post detailed recovery and affected-user information to Discord. The platform remains operational. The full list of attacker wallets and a detailed memo on the incident mechanics have not yet been disclosed.