Fortress Protocol Hacked for $3 Million, Drained of All Funds

0

[ad_1]

Fortress Protocol – an algorithmic money market and defi lending protocol – has been drained of all funds following an oracle manipulation attack. The stolen crypto has since been bridged from Binance Smart Chain to Ethereum and mixed using the privacy protocol Tornado Cash.

Buying Out the Protocol

Blockchain security firm CertiK shared information about the hack with CryptoPotato on Monday. It began with the hacker using ETH to purchase a substantial amount of FTS – the governance token managing the FTS protocol.

The quorum votes on Fortress loans’ governance contract is 400,000 FTS. That was worth just $18,000 at the time of the hack and represented a smaller number of tokens than the attacker held. In other words, he now held the authority to pass any protocol change proposal that he liked.

As such, he passed proposal ID 11, which changed the collateral factor on FTS tokens within loan contracts from 0 to 700,000,000,000,000,000. He also updated the price oracle used by the loan contract such that the token’s price would update, even if voting power was zero.

“With these updates, the value of the attacker’s collateral (FTS) was raised significantly, so the attacker was able to borrow large amounts of other tokens from the loan contracts,” explained CertiK over Twitter.

The attacker used his remaining FTS to borrow a massive number of tokens, and convert them to over 1000 ETH, and over 400,000 DAI – worth over $3 million at the time of the hack. He then deployed a self-destruct mechanism encoded into his malicious smart contract and swiftly transferred the stolen goods to Tornado Cash.

The fortress protocol team said they are “absolutely devastated” by yesterday’s events. They have called on the community to not deposit any assets into Fortress, and for all available partners to assist in reclaiming the funds.

Tornado Cash: Criminal Tool of Choice

Both the ETH required to purchase the hacker’s initial FTS, and the ETH representing the hacker’s stolen goods came and went through Tornado Cash. The mixing protocol breaks the link between a sender and receiver’s address on Ethereum, letting the hacker keep his identity concealed from start to finish.

The same protocol has been useful to numerous crypto thieves over the past few months. The person or group behind the $600 million Ronin hack in March is now solely responsible for 15% of funds being deposited into the mixer.

In January, an approximate $14.6 million in ETH stolen from Crypto.com was laundered through Tornado.

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 86,308.00
ethereum
Ethereum (ETH) $ 2,921.82
tether
Tether (USDT) $ 0.999750
bnb
BNB (BNB) $ 863.49
xrp
XRP (XRP) $ 1.90
usd-coin
USDC (USDC) $ 0.999926
tron
TRON (TRX) $ 0.279029
staked-ether
Lido Staked Ether (STETH) $ 2,921.35
dogecoin
Dogecoin (DOGE) $ 0.129721
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
cardano
Cardano (ADA) $ 0.377602
whitebit
WhiteBIT Coin (WBT) $ 57.18
wrapped-steth
Wrapped stETH (WSTETH) $ 3,570.80
bitcoin-cash
Bitcoin Cash (BCH) $ 545.87
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 86,007.00
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,172.91
usds
USDS (USDS) $ 0.999791
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999718
chainlink
Chainlink (LINK) $ 12.64
wrapped-eeth
Wrapped eETH (WEETH) $ 3,167.41
leo-token
LEO Token (LEO) $ 9.01
monero
Monero (XMR) $ 428.34
weth
WETH (WETH) $ 2,922.22
hyperliquid
Hyperliquid (HYPE) $ 26.85
stellar
Stellar (XLM) $ 0.215882
ethena-usde
Ethena USDe (USDE) $ 0.998990
zcash
Zcash (ZEC) $ 389.03
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 86,323.00
litecoin
Litecoin (LTC) $ 78.16
sui
Sui (SUI) $ 1.47
avalanche-2
Avalanche (AVAX) $ 12.10
hedera-hashgraph
Hedera (HBAR) $ 0.111802
susds
sUSDS (SUSDS) $ 1.08
shiba-inu
Shiba Inu (SHIB) $ 0.000008
dai
Dai (DAI) $ 0.999786
usdt0
USDT0 (USDT0) $ 0.999610
mantle
Mantle (MNT) $ 1.27
paypal-usd
PayPal USD (PYUSD) $ 0.999856
the-open-network
Toncoin (TON) $ 1.50
world-liberty-financial
World Liberty Financial (WLFI) $ 0.133110
crypto-com-chain
Cronos (CRO) $ 0.094099
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
uniswap
Uniswap (UNI) $ 5.08
polkadot
Polkadot (DOT) $ 1.86
memecore
MemeCore (M) $ 1.68
aave
Aave (AAVE) $ 183.81
usd1-wlfi
USD1 (USD1) $ 0.999068
canton-network
Canton (CC) $ 0.071162
rain
Rain (RAIN) $ 0.007589
bitget-token
Bitget Token (BGB) $ 3.50
Shares