Decentralized anonymous lottery protocol Foom Cash suffered a loss of approximately $2.26 million due to a security breach. According to ChainCatcher, a white-hat hacker intervened promptly, recovering $1.84 million, which accounts for 81% of the stolen funds.
The security incident was caused by a critical error during Foom Cash's deployment process, specifically involving a Groth16 verifier configuration issue. This flaw allowed attackers to submit forged proofs to the protocol. A white-hat hacker, known by the alias Duha, identified the vulnerability and swiftly secured the funds on the Base chain. Meanwhile, security firm Decurity managed the recovery efforts for funds on the Ethereum network.
In recognition of their efforts, Foom Cash rewarded the white-hat hacker with a $320,000 bounty and paid Decurity $100,000 for their security services.