SushiSwap approval bug leads to $3.3M exploit

0

[ad_1]

A bug on a smart contract on the decentralized finance (DeFi) protocol SushiSwap led to over $3 million in losses in the early hours of April 9, according to several security reports on Twitter. 

Blockchain security companies CertiK Alert and Peckshield posted about an unusual activity related to the approval function in Sushi’s Router Processor 2 contract — a smart contract that aggregates trade liquidity from multiple sources and identifies the most favorable price for swapping coins. Within a few hours, the bug led to losses of $3.3 million.

According to DefiLlama pseudonymous developer 0xngmi, the hack should only affect users who swapped in the protocol in the past four days.

Sushi’s head developer, Jared Grey, urged users to revoke permissions for all contracts on the protocol. “Sushi’s RouteProcessor2 contract has an approval bug; please revoke approval ASAP. We’re working with security teams to mitigate the issue,” he said. A list of contracts on GitHub with different blockchains requiring revocation has been created to address the problem.

Hours after the incident, Grey took to Twitter to announce that a ”large portion of affected funds” had been recovered through a white hat security process. “We’ve confirmed recovery of more than 300ETH from CoffeeBabe of Sifu’s stolen funds. We’re in contact with Lido’s team regarding 700 more ETH.”

The Sushi community has had an intense weekend. On April 8, Grey and his counsel provided comments on the recent subpoena from the United States Securities and Exchange Commission.

“The SEC’s investigation is a non-public, fact-finding inquiry trying to determine whether there have been any violations of the federal securities laws. To the best of our knowledge, the SEC has not (as of this writing) made any conclusions that anyone affiliated with Sushi has violated United States federal securities laws,” he stated.

Grey claims to be cooperating with the investigation. A legal defense fund in response to the subpoena was proposed on Sushi’s governance forum on March 21.

Magazine: Hodler’s Digest, April 2-8: BTC white paper hidden on macOS, Binance loses AUS license and DOGE news



[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 86,969.30
ethereum
Ethereum (ETH) $ 2,923.53
tether
Tether (USDT) $ 0.999995
xrp
XRP (XRP) $ 2.17
bnb
BNB (BNB) $ 858.28
solana
Wrapped SOL (SOL) $ 137.95
usd-coin
USDC (USDC) $ 0.999986
tron
TRON (TRX) $ 0.274320
staked-ether
Lido Staked Ether (STETH) $ 2,920.28
dogecoin
Dogecoin (DOGE) $ 0.150175
cardano
Cardano (ADA) $ 0.418601
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.01
whitebit
WhiteBIT Coin (WBT) $ 57.54
wrapped-steth
Wrapped stETH (WSTETH) $ 3,564.61
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 86,896.28
bitcoin-cash
Bitcoin Cash (BCH) $ 527.36
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,165.29
usds
USDS (USDS) $ 0.999892
hyperliquid
Hyperliquid (HYPE) $ 33.69
chainlink
Chainlink (LINK) $ 12.93
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999877
leo-token
LEO Token (LEO) $ 9.66
zcash
Zcash (ZEC) $ 513.92
stellar
Stellar (XLM) $ 0.248672
weth
WETH (WETH) $ 2,921.71
wrapped-eeth
Wrapped eETH (WEETH) $ 3,159.32
ethena-usde
Ethena USDe (USDE) $ 0.998667
monero
Monero (XMR) $ 395.24
litecoin
Litecoin (LTC) $ 84.47
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 86,985.31
hedera-hashgraph
Hedera (HBAR) $ 0.144223
avalanche-2
Avalanche (AVAX) $ 14.02
sui
Sui (SUI) $ 1.52
shiba-inu
Shiba Inu (SHIB) $ 0.000009
world-liberty-financial
World Liberty Financial (WLFI) $ 0.171243
dai
Dai (DAI) $ 1.00
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
crypto-com-chain
Cronos (CRO) $ 0.108857
usdt0
USDT0 (USDT0) $ 0.999514
susds
sUSDS (SUSDS) $ 1.08
uniswap
Uniswap (UNI) $ 6.15
the-open-network
Toncoin (TON) $ 1.55
paypal-usd
PayPal USD (PYUSD) $ 0.999966
polkadot
Polkadot (DOT) $ 2.26
mantle
Mantle (MNT) $ 1.01
memecore
MemeCore (M) $ 1.87
canton-network
Canton (CC) $ 0.089507
bittensor
Bittensor (TAO) $ 306.92
usd1-wlfi
USD1 (USD1) $ 0.999036
aave
Aave (AAVE) $ 176.80
Shares