A few hours ago, some Loopring smart wallets suffered a security breach. The attack exploited wallets that had only one guardian, specifically the Loopring Official Guardian. The hacker initiated a recovery process, impersonating the wallet owner to reset ownership and withdraw assets.
The attack successfully compromised Loopring's 2FA service, allowing the hacker to impersonate the wallet owner and obtain recovery approval from the Official Guardian. The attacker then transferred the assets out of the affected wallets.
Loopring says it is currently actively working with Mist security experts to determine how its 2FA service was compromised. To protect users, operations related to Guardian and 2FA have been suspended for the time being.
Loopring is working with law enforcement and professional security teams to track down the perpetrators. Updates will continue to be provided as the investigation progresses.
The hacker addresses involved are:
0x44f887cfbd667cb2042dd55ab1d8951c94bb0102
0xbacef3a142e39f14f4f15e22e9248ee4141af18f