Post-mortem on the October 5 incident
On October 5, we discovered that a malicious actor found a vulnerability in one o | Hanami
Post-mortem on the October 5 incident
On October 5, we discovered that a malicious actor found a vulnerability in one of our backend services.
This allowed them to move approximately $5.8k in funds out of 36 accounts. Stolen funds were contained to a small subset of users and select assets they held. No private keys (held remotely with Privy) were exposed.
The attacker was also able to access some profile-level details, including email addresses - we will email each affected user with a personalized impact report. We will not include any links or requests to take action in this email. Please take extra precaution around phishing attempts and scammers impersonating Wayfinder.
The vulnerability lived in a backend service we built in 2025 to simulate contract interactions for users building smart contracts on Wayfinder. The attacker tricked the service into revealing an access key, allowing them to reach several other credentials we use to run Wayfinder.
We’re truly sorry to all users who were impacted. Trust must be earned through action, and we’ve taken many steps in the past days to strengthen our security, making any future exploit attempts far more difficult, and far better contained.
After discovering the attack, we:
Immediately froze our services and revoked all permissions across our stack to prevent further user impact.
Suspended all user Shells (virtual private servers).
Assessed the user impact; announced the exploit to users and intention to compensate the losses.
Identified the source of the exploit and all additional surface areas impacted.
Reviewed and rebuilt our infrastructure, strengthening security in dozens of areas.
Compensated Shells users who had funds stolen.
Partially restored Wayfinder, enabling users to manage their positions through the UI tools.
Early next week, we’ll:
Email a personalized impact report to every affected user.
Fully restore Wayfinder, including freshly deployed Shells and agents (we’re still reviewing potential attack surfaces).
Compensate users whose positions were stuck and which resulted in loss while Wayfinder was paused.
Compensate legacy app users who had funds stolen.
Officially retire the legacy app (v1, which was used until May 2026). If you still have a balance there, you’ll still be able to export your keys to manage your positions.
These actions make Wayfinder significantly more secure, and we hope they are the first step towards earning back your trust. Our work to keep raising the bar on security doesn’t stop here.
- The Wayfinder Team