The Tapioca Foundation has announced a $1 million reward for the individual responsible for stealing $4.7 million from its decentralized finance (DeFi) protocol. This amount significantly exceeds the typical 10% bounty commonly offered in similar situations.
Request for Return of Remaining Funds
In exchange for the reward, Tapioca requested the return of the remaining $3.7 million. The breach occurred on October 18 and involved the theft of 591 Ether (ETH) and $2.8 million in USD Coin (USDC). According to the foundation, the attacker exploited a weakness in the vesting contract for its TAP token and the USDO stablecoin.
The attacker was able to claim and sell vested TAP tokens and manipulated the USDO stablecoin by adding a minter, resulting in an infinite supply and draining a liquidity pool containing USDO and USDC. Tapioca co-founder Matt Marino provided additional insights on the project’s Discord channel, revealing that his co-founder, known by the pseudonym “Rektora,” had been phished during an interview process.

Recovery of Stolen Assets
Rektora accidentally downloaded malicious software that altered a transaction, granting the attacker access to crucial contracts. In an unexpected development, Marino later announced that Tapioca successfully managed to “hack the hacker” and recover 1,000 ETH, valued at over $2.7 million, which had served as collateral backing the USDO stablecoin in a liquidity pool.
Despite the recovery of some assets, the attack had a detrimental impact on the TAP token’s value, which dropped from approximately $1.40 to just 2 cents following the incident, according to CoinGecko. The attacker still holds funds on the BNB Chain, and it remains uncertain whether they will return the remaining stolen assets.
Rise in Phishing Scams
Phishing attacks continue to pose a significant threat to crypto users, leading to considerable losses. In September, over 10,000 individuals fell victim to various scams, resulting in losses exceeding $46 million, according to Scam Sniffer, a Web3 anti-scam platform.
Ongoing Cybersecurity Challenges
The platform reported that 10,805 victims experienced losses amounting to $46.7 million due to crypto phishing scams last month. Recently, it was revealed that cybersecurity scammers are employing automated email replies to infiltrate systems and deliver stealthy crypto mining malware.
This follows another malware threat identified in August, known as the “Cthulhu Stealer,” which targets MacOS systems while disguising itself as legitimate software. It aims to steal personal information, including MetaMask passwords, IP addresses, and private keys from cold wallets.
Additionally, a fraudulent crypto wallet app on Google Play has reportedly siphoned $70,000 from users in a sophisticated scam that targets mobile users exclusively. This malicious app, named WalletConnect, masqueraded as the legitimate WalletConnect protocol but was actually a sophisticated scheme designed to drain crypto wallets.
Disclaimer: This content does not constitute trading or investment recommendations. It’s essential to conduct your own research before purchasing any cryptocurrency or investing in any services.















