지금 프로젝트를 보호하세요
최대 규모의 웹3 보안 제공업체로 프로젝트를 강화하세요.
CertiK 보안 전문가가 귀하의 요청을 검토 후 곧 연락드리겠습니다.

unshETH Private Key Slip: $375,000 Loss from a Github Post

보고서 ·사고 분석 ·
unshETH Private Key Slip: $375,000 Loss from a Github Post

Project name: unshETH

Project type: Staking

Date of exploit: June 1, 2023

Asset loss: $375,000

Vulnerability: Private key leak

Date of audit report publishing: 03/23/2023

Conclusion: Out of audit scope

Details of the Exploit

Background

unshiETH is a staking platform that allows users to stake ETH and earn yield and swap fees. The exploited contract unshiETH Farm contains users’ unshiETH for farming.

Nature of the Vulnerability

The attacker compromised the private key of the unshiETH, which allows the attacker to withdraw the asset from the protocol.

CertiK Audit Overview

Screenshot 2024-01-08 at 5.10.33 AM

Screenshot 2024-01-08 at 5.11.16 AM

Conclusion

On Jun 01, 2023, the staking platform unshETH was attacked, leading to a loss of around $375,000. According to the unshETH team, they mistakenly leaked their private key to Github, which allows users to withdraw unshETH from the contract. It was due to a human error of the private key management, which should be out of the audit scope.

Reference

Other Resources:

관련 블로그

Skynet Wrench Attacks Report

Skynet Wrench Attacks Report

In 2025, wrench attacks unfortunately crossed a critical threshold. What was once treated as an edge-case risk has become a structural threat to digital asset ownership. Attackers are no longer acting opportunistically; they are operating as organized, transnational groups that combine OSINT-driven targeting, social engineering, and extreme physical violence to extract private keys.

CertiK, 2025년 Skynet Hack3d 보안 보고서 발표!

CertiK, 2025년 Skynet Hack3d 보안 보고서 발표!

CertiK이 2025 Skynet Hack3D 보안 보고서를 발표했습니다. 본 보고서는 블록체인 및 스마트 컨트랙트 보안을 규정하는 주요 공격 사례, 취약점, 그리고 트렌드를 심층적으로 분석합니다. 또한 개별 사건에 대한 상세 분석과 기술적 인사이트는 물론, Web3 업계 전반의 해킹·사기·취약점 악용 사례에 대한 가장 포괄적인 통계가 담겨 있습니다.

Private Key, Public Risk

Private Key, Public Risk

In Web3, private keys are critical for controlling assets, governance, and trust, but their mismanagement poses significant risks, including financial loss and reputational damage. This article explores secure private key generation, storage, and usage to mitigate these vulnerabilities.