Ordswap Chronicles: Navigating Challenges

Martin Walker
Oct 11, 2023 at 09:15 am

Ordswap, an innovative marketplace catering to users looking to inscribe, auction, and trade Bitcoin Ordinals, has ingeniously devised a practical method to facilitate the retrieval of private keys for users, all while navigating the complex endeavor of regaining control over its website domain.

In a recent tweet posted on October 10th by the esteemed Ordswap X account, an invaluable online tool was graciously shared, purportedly engineered to come to the aid of MetaMask users, allowing them to delicately and securely retrieve their Ordswap private keys. This thoughtful provision empowers them to elegantly transition their digital assets and activities to alternative service providers, should they so choose.

Preceding this momentous tweet, during the early hours of October 9th, Ordswap issued a candid and forthright caution to its valued users, earnestly advising them against establishing any connections with its domain. The justification for this solemn advisory was attributed to an unfortunate loss of control over the domain, for which the accountability was tactfully placed at the doorstep of Netlify, a well-known and reputable entity specializing in website development and hosting.

In a closely-knit community bound by the shared interest in Ordswap, particularly within the project's dedicated Discord server, one could find earnest interactions and exchanges of concerns. A member of Ordswap's esteemed team, together with vigilant users, collaborated to report a concerning incident. During a specific period, the website displayed a rather conspicuous button, seemingly beckoning users to establish a secure link with their esteemed crypto wallets. This raised suspicions of a potentially deceptive intent behind the interface design, casting a shadow of doubt on the website's integrity.

Intriguingly, a meticulous user noted that the aforementioned button might indeed be a "wallet drainer," a notorious tool of choice in the repertoire of unscrupulous crypto scammers. The situation escalated as Ordswap's website, at the time of this comprehensive report, autonomously directed users to a competing marketplace named RelayX. This development, undoubtedly, added another layer of intrigue to the unfolding narrative.

In an attempt to assuage concerns within the community, a compassionate and vigilant Ordswap team member took to Discord to provide valuable insights. They reassuringly communicated that, up to that very moment, the breach had not wrought havoc upon user private keys or assets. However, a word of caution was thoughtfully interwoven into their message, imploring users to exercise discernment and prudence while interacting with the site, recognizing the potential risks that lingered in the digital realm.

Ordswap support team member “Bitkorn” claims the project hasn’t seen user assets impacted by the website’s breach. Source: DiscordOrdswap support team member “Bitkorn” claims the project hasn’t seen user assets impacted by the website’s breach. Source: Discord

Recalling events from late September, the crypto community bore witness to a distressing incident involving Balancer, a prominent Ethereum-based automated market maker. This attack bore an unsettling resemblance to the ongoing ordeal with Ordswap. In a disconcerting turn of events, the assailants successfully absconded with a significant sum totaling around $240,000. Balancer, in a display of transparency and responsibility, elucidated their belief that the exploiters had orchestrated a sophisticated social engineering attack on their DNS service provider, EuroDNS. This elaborate ruse enabled the attackers to surreptitiously input a deceptive prompt, cunningly deceiving users into approving a malicious contract, ultimately leading to the unfortunate depletion of their cherished digital wallets. Such incidents underscore the imperative for continued vigilance and collaboration within the crypto community, reinforcing the collective dedication to fortifying the security and resilience of digital assets and platforms alike.

