DeFi Protocol Sturdy Finance Exploited for 442 ETH Worth Almost $800K

0

[ad_1]

Sturdy Finance – a DeFi project promising up to 10x leverage on staked assets – has been exploited by a hit-and-run attack on its pricing oracle.

Although the amount stolen (worth about $800k at the time this article was written) pales in comparison to other, more high-profile attacks like the one on Atomic Wallet users just last week, it also ensures that laundering the profits will not be nearly as hard as it is for cybercriminals who have made off with much bigger takings.

Price Manipulation

The attack on Sturdy Finance was carried out via reentrancy exploit, a common method of attacking DeFi projects that entails repeatedly calling a function in a smart contract before the original call is completed.

In order to attack Sturdy Finance, the hacker first established the vulnerability of the protocol’s price oracle – the part of Sturdy’s ecosystem that determines the current value of assets to be used in trading and loans – to reentrancy exploits. Once the vulnerability was established, a flashloan from AAVE provided the liquidity necessary for the attack.

This allows the bad actor to withdraw more funds than the smart contract should allow them to. In this case, the price of staked Ether (stETH) was manipulated three times in a row in order to enable the bad actor to withdraw more than the loan should allow them to, pay off the original loan, and cash out the extra funds. This process was then repeated on five occasions, each time using a different smart contract.

The exploit resulted in a loss of 442 ETH for Sturdy, a takeaway already on its way to Tornado Cash.

Post-Mortem in Progress

The security team at Sturdy confirmed that the exploit has been noted, and their operations have been paused for the moment to conduct a proper post-mortem. The team also asserted that no other funds are currently at risk of being stolen.

“We are aware of the reported exploit of the Sturdy protocol. All markets have been paused; no additional funds are at risk, and no user actions are required at this time. We will be sharing more information as soon as we have it.”

Sturdy’s community is understandably upset at the news, with some users proclaiming disbelief that attacks typical of the 2017 shitcoin boom era are still happening today.

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter CRYPTOPOTATO50 code to receive up to $7,000 on your deposits.



[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 0.000000
ethereum
Ethereum (ETH) $ 0.000000
tether
Tether (USDT) $ 0.000000
bnb
BNB (BNB) $ 0.000000
xrp
XRP (XRP) $ 0.000000
usd-coin
USDC (USDC) $ 0.000000
tron
TRON (TRX) $ 0.000000
staked-ether
Lido Staked Ether (STETH) $ 0.000000
dogecoin
Dogecoin (DOGE) $ 0.000000
figure-heloc
Figure Heloc (FIGR_HELOC) $ 0.000000
cardano
Cardano (ADA) $ 0.000000
whitebit
WhiteBIT Coin (WBT) $ 0.000000
wrapped-steth
Wrapped stETH (WSTETH) $ 0.000000
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 0.000000
bitcoin-cash
Bitcoin Cash (BCH) $ 0.000000
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 0.000000
usds
USDS (USDS) $ 0.000000
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.000000
chainlink
Chainlink (LINK) $ 0.000000
wrapped-eeth
Wrapped eETH (WEETH) $ 0.000000
leo-token
LEO Token (LEO) $ 0.000000
weth
WETH (WETH) $ 0.000000
monero
Monero (XMR) $ 0.000000
hyperliquid
Hyperliquid (HYPE) $ 0.000000
stellar
Stellar (XLM) $ 0.000000
zcash
Zcash (ZEC) $ 0.000000
ethena-usde
Ethena USDe (USDE) $ 0.000000
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 0.000000
litecoin
Litecoin (LTC) $ 0.000000
sui
Sui (SUI) $ 0.000000
avalanche-2
Avalanche (AVAX) $ 0.000000
usdt0
USDT0 (USDT0) $ 0.000000
hedera-hashgraph
Hedera (HBAR) $ 0.000000
susds
sUSDS (SUSDS) $ 0.000000
shiba-inu
Shiba Inu (SHIB) $ 0.000000
dai
Dai (DAI) $ 0.000000
mantle
Mantle (MNT) $ 0.000000
paypal-usd
PayPal USD (PYUSD) $ 0.000000
the-open-network
Toncoin (TON) $ 0.000000
world-liberty-financial
World Liberty Financial (WLFI) $ 0.000000
crypto-com-chain
Cronos (CRO) $ 0.000000
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 0.000000
uniswap
Uniswap (UNI) $ 0.000000
polkadot
Polkadot (DOT) $ 0.000000
memecore
MemeCore (M) $ 0.000000
aave
Aave (AAVE) $ 0.000000
usd1-wlfi
USD1 (USD1) $ 0.000000
rain
Rain (RAIN) $ 0.000000
canton-network
Canton (CC) $ 0.000000
bittensor
Bittensor (TAO) $ 0.000000
Shares