In the early hours of this morning, Optimism and the market maker Wintermute both issued announcements, disclosing to the community an accidental "stolen" incident of 20 million OP tokens.

Affected by this bad news, OP quickly dived in the secondary market, the lowest once fell below 0.7 USDT, and as of the publication, it was tentatively reported at 0.786 USDT.
Combining the statements of both Optimism and Wintermute, we can roughly sum up the process of this matter.
The background of the matter is that when the OP token was issued, Optimism entrusted Wintermute to provide liquidity services for OP in the secondary market. As part of the agreement, Optimism will provide 20 million OP tokens to Wintermute.
In order to receive this token, Wintermute gave Optimism a multi-signature address (0x4f3a120E72C76c22ae802D129F599BFDbc31cb81). After Optimism tested and sent two transactions and Wintermute confirmed that they were correct, Optimism transferred 20 million OP to this address.
At this time, the problem came out. After Optimism completed the currency transfer, Wintermute found that it could not control these tokens, because the multi-signature address they provided was only deployed on the Ethereum mainnet for the time being, and had not yet been deployed to the Optimism network.
Note: Multi-signature addresses are different from ordinary addresses, and the controls on L1 and L2 are not exactly one-to-one correspondence.
In order to control these tokens, Wintermute immediately launched a remedial operation, hoping to deploy the multi-signature contract to the same address on the Optimism network.
Unfortunately, before Wintermute, an attacker had noticed this vulnerability and deployed multi-signature to the address of the Optimism network before Wintermute, successfully controlling the 20 million tokens.
That's how the whole thing came about, the hackers have now managed to take control of the tokens and the first million tokens were sold three days ago.
So what's Optimism and Wintermute's current plan to remedy?
First of all, in order to keep the market-making work going, Optimism has provided Wintermute with a second tranche of 20 million OP, for which Wintermute paid a deposit of 50 million US dollars.
Secondly, Wintermute has admitted that it is 100% fully responsible for this matter, and has also promised to repurchase the same amount of tokens. For the 1 million OPs that the hacker had previously sold, Wintermute completed the first repurchase yesterday.
Finally, Wintermute hopes to recover the lost 20 million OP through hard and soft measures. The specific method is to give the hacker a week to think. If he is willing to return the tokens, he will be regarded as a white-hat hacker. Search to identify the hacker and hand it over to the judiciary.

As of the publication (after the announcement of Optimism and Wintermute), the control controlled by hackers has changed again - 1 million OPs have been transferred out for the second time, but this time they are not sold, but directly transferred to V God's address (0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045) , it is not sure what the hacker is thinking, nor can it be determined whether the remaining 18 million OP may be returned.


