Attacker Steals $11M Worth of Crypto

0

[ad_1]

Not one, but two decentralized finance (DeFi) protocols – Agave and Hundred Finance – were exploited in a fresh case of a “re-entrancy” attack.

The hacker reportedly managed to siphon funds worth $11 million in Wrapped ETH, Wrapped BTC, Chainlink, USDC, Gnosis, and Wrapped XDAI on both DeFi protocols on the Gnosis chain using a flash loan exploit.

The Hacks

Gauging at the data available on Tenderly for both breaches, it was found that the hacker exploited a re-entrancy bug in the two protocols.

For the uninitiated, “re-entrancy” is a vulnerability in the Solidity programming language that enables a malicious entity to deceive a protocol’s smart contract into making an external call to an untrusted contract. After the attacker gains control of the untrusted contract, they can make recursive calls to the original function to drain its funds.

Blockchain and security researcher, Mudit Gupta, revealed that the official bridged tokens on Gnosis are the main culprit and stated that they are “non-standard and have a hook that calls the token receiver on every transfer.” He added that this is what allows re-entrancy attacks.

Agave is a fork of DeFi lending platform Aave, while the multi-chain lending project, Hundred Finance, is a fork of Compound. Gupta also claimed that Compound does not follow the recommended checks-effects-interactions pattern despite referring to it.

The re-entrancy attacks become more staggering since “the code executes interactions before applying the effects.” On the other hand, Aave tries to follow the aforementioned checks-effects-interactions pattern. However, there exists a path via liquidations using which the attacker “broke the pattern” in the recent attack. He went on to add,

“The agave and hundred protocol teams messed up by listing a token that can reenter. Aave and compound governance actively check for reentrancy before listing tokens on the mainnet to avoid similar attacks.”

Popular DeFi lending platform Cream Finance, which shares a similar codebase to that of Compound, was also exploited in an $18.8 million flash loan reentrancy attack in August last year.

Funds Are Not SAFU

According to a developer at DeFi protocol DanceFloor, “Shegan,” the funds are not safe. However, Martin Köppelmann, the founder of Gnosis, said he would support a measure from the DAO. The team behind Hundred Finance and Agave is currently investigating the exploits and has paused the contracts.

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 86,913.29
ethereum
Ethereum (ETH) $ 2,836.24
tether
Tether (USDT) $ 0.999954
xrp
XRP (XRP) $ 2.07
bnb
BNB (BNB) $ 850.08
usd-coin
USDC (USDC) $ 0.999954
tron
TRON (TRX) $ 0.276751
staked-ether
Lido Staked Ether (STETH) $ 2,833.18
dogecoin
Dogecoin (DOGE) $ 0.146349
cardano
Cardano (ADA) $ 0.412876
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
whitebit
WhiteBIT Coin (WBT) $ 56.76
wrapped-steth
Wrapped stETH (WSTETH) $ 3,459.21
bitcoin-cash
Bitcoin Cash (BCH) $ 545.65
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 86,739.24
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,074.86
usds
USDS (USDS) $ 0.999934
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999828
chainlink
Chainlink (LINK) $ 12.62
zcash
Zcash (ZEC) $ 533.12
leo-token
LEO Token (LEO) $ 9.47
hyperliquid
Hyperliquid (HYPE) $ 31.36
stellar
Stellar (XLM) $ 0.248298
weth
WETH (WETH) $ 2,834.36
ethena-usde
Ethena USDe (USDE) $ 0.998618
wrapped-eeth
Wrapped eETH (WEETH) $ 3,063.34
monero
Monero (XMR) $ 381.64
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 86,864.27
litecoin
Litecoin (LTC) $ 83.77
hedera-hashgraph
Hedera (HBAR) $ 0.147974
avalanche-2
Avalanche (AVAX) $ 13.43
sui
Sui (SUI) $ 1.39
shiba-inu
Shiba Inu (SHIB) $ 0.000008
dai
Dai (DAI) $ 0.999584
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.20
world-liberty-financial
World Liberty Financial (WLFI) $ 0.156261
usdt0
USDT0 (USDT0) $ 0.999459
crypto-com-chain
Cronos (CRO) $ 0.106425
uniswap
Uniswap (UNI) $ 6.30
susds
sUSDS (SUSDS) $ 1.08
polkadot
Polkadot (DOT) $ 2.28
the-open-network
Toncoin (TON) $ 1.47
paypal-usd
PayPal USD (PYUSD) $ 0.999986
memecore
MemeCore (M) $ 1.95
mantle
Mantle (MNT) $ 1.02
canton-network
Canton (CC) $ 0.085112
bittensor
Bittensor (TAO) $ 288.15
usd1-wlfi
USD1 (USD1) $ 0.998835
aave
Aave (AAVE) $ 171.38
bitget-token
Bitget Token (BGB) $ 3.54
Shares