Pundi AI recovered 87% of its assets after being attacked by a Hacker and was delisted by the Korean exchange due to untimely information disclosure.

robot
Abstract generation in progress

Hacker Attacks, Asset Recovery, and Exchange Delisting: The Dilemmas and Future Outlook for Pundi AI

On July 12, Pundi AI suffered a Hacker attack, resulting in an abnormal issuance of 1 million tokens. In response to the crisis, the team quickly took action to freeze, track, and recover assets, while promptly disclosing the situation to the community. Ultimately, they successfully recovered and froze nearly 90% of the stolen funds and advanced over a million dollars to complete full user compensation. However, Pundi AI was notified by the Digital Asset Exchange Association (DAXA) to be delisted from Korean exchanges due to "untimely information disclosure."

Key Timeline of Events:

  • March 2: Function X announced a rebranding to PUNDIAI, with a token swap to PUNDI.
  • July 12: Hacker launched an attack, resulting in an abnormal issuance of 1 million tokens; the team froze transfers and initiated tracking; the CEO publicly disclosed the contract vulnerability to the community.
  • July 14: Disclose the investigation results and solutions of the attack incident to the exchange, and communicate with DAXA.
  • July 28: Some exchanges announced the delisting of PundiAI on August 28.
  • July 31: Official statement recovers over 80% of assets, full user compensation completed within 11 days.

PANews exclusively interviews Danny Lim, co-founder of Pundi AI, reviewing the event process comprehensively and providing safety and compliance operation reminders for other projects in the industry. Danny also discusses Pundi AI's product layout in the AI data field and his thoughts on the development of the Web3 AI track.

In the process of fighting against hackers, the project faces a dilemma: should it prioritize ensuring the safety of user funds without alarming the hackers, or should it maintain transparency and prioritize the disclosure of information, which could potentially lead to hackers accelerating the transfer of funds? Pundi AI chose the former, but paid the price for the "flaw" in transparency.

The delisting from a compliant exchange has instead brought new opportunities for project development. Previously constrained by exchange rules, it is now possible to flexibly utilize token economics to give back to the community. Pundi AI plans to repurchase tokens and airdrop them to users to thank them for their support during difficult times.

Forced to leave after 5 years in Korea, is Pundi AI's priority to protect user assets a "wrong decision"?

Hacker Attack Incident Details

On the afternoon of July 12, the Pundi AI system warning indicated an abnormal minting of approximately 1 million PUNDI tokens. The team initially judged it to be a contract bug, but after verification, it was confirmed to be a Hacker attack. The Hacker exploited a vulnerability in the token migration contract to gain administrator privileges ahead of the project deploying a new contract.

To maximize the recovery of assets, the team decided to avoid alarming the Hacker, secretly tracking and freezing the assets. This strategy proved effective, successfully intercepting about 95% of the stolen assets. The main losses occurred on the BSC chain due to the delayed response from the cross-chain bridge service provider over the weekend.

In the end, approximately 6 million dollars worth of tokens were issued, the team recovered 87% of the assets, and incurred a loss of nearly 2 million dollars. Full compensation will be provided to users affected by the market crash.

After being forced to leave Korea for 5 years, is Pundi AI's priority to protect user assets a "wrong decision"?

Communication with DAXA and delisting handling

The team had multiple rounds of communication with DAXA, detailing the technical specifics, solutions, and user compensation situation. However, DAXA ultimately requested delisting on the grounds of "untimely disclosure," without providing a chance for defense.

Danny stated that this decision left the team feeling regretful and "heartbroken". Compared to other similar incidents, Pundi AI actively compensated users and recovered assets, yet faced delisting. This serves as a wake-up call for projects operating in the South Korean market: timeliness and transparency of information are crucial.

Adjustment of Market Strategy in South Korea

Pundi AI entered the South Korean market in 2019 and has accumulated a large number of users. South Korean users heavily rely on centralized exchanges, and this delisting has a huge impact on the project's liquidity.

The team is actively communicating with DAXA and major exchanges to strive for a return to the Korean market. At the same time, they will increase investment in decentralized exchanges to provide users with ample liquidity.

Forced to leave after 5 years in Korea, is Pundi AI's priority to protect user assets a "wrong decision"?

AI Data Product Data Pump

Pundi AI's new product Data Pump is an "AI Dataset Launchpad" designed to enable data tokenization. Users can package content data into NFTs, collateralize them to generate tokens, and trade on DEX.

Unlike other AI data projects, Pundi AI focuses on high-quality professional data, developing AI AMM to realize data assetization, and has a large data foundation.

Web3 AI Development Outlook

Danny believes that the bottleneck in the development of Web3 AI lies in the lack of practical applications that change lives. Decentralized computing power is currently insufficient to support large language models. The true value of blockchain in the AI field is to protect user data sovereignty and privacy.

The future development of the Web3 AI track may require traditional AI giants to actively embrace blockchain technology to provide users with data protection features, thereby driving the development of the entire industry.

Forced to leave after 5 years in Korea, is Pundi AI's priority to protect user assets a "mistake"?

PUNDIAI1.67%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 3
  • Share
Comment
0/400
MidnightSnapHuntervip
· 08-06 18:41
The funds were recovered quite quickly.
View OriginalReply0
GasWaster69vip
· 08-06 12:54
Delisting is only temporary.
View OriginalReply0
DaoGovernanceOfficervip
· 08-06 12:39
DAXA lacks governance clarity
Reply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)