Bitcoin Defi Protocol Sovryn Gets Hacked for Over $1 Million

0

[ad_1]

Sovryn – a Bitcoin-based decentralized finance protocol – was drained of over $1 million in funds on Tuesday using a price manipulation exploit. 

The attack allowed the culprit to drain over $1 million worth of crypto from the protocol, including 44.93 RBTC and 211,045 USDT.

Sovryn’s First Hack

According to Sovryn’s blog post on the topic, the attacks specifically targeted the legacy Sovryn Borrow/Lend protocol. It impacted the RBTC and USDT lending pools. 

RBTC and USDT are crypto assets price pegged to Bitcoin and US dollars respectively. In this case, they circulate on Rootstock (RSK), a Bitcoin sidechain meant to expand Bitcoin’s smart contract, dapp, and scaling capabilities. Sovryn is a Defi protocol built on RSK. 

Some of the funds were apparently withdrawn using Sovryn’s AMM swap function, meaning the attacker ended up with several different tokens. The effort to recover funds is still ongoing. 

“Due to the multi-layered security approach taken, devs were able to identify and recover funds as the attacker was attempting to withdraw the funds,” reads the post. “At this point, through a combined effort, devs have managed to recover about half the value of the exploit.”

Sovryn spokesperson Edan Yago said this is the first successful exploit against the protocol after two years of operation. He maintained that Sovryn is “one of the most heavily audited Defi systems,” with valuable and active bug bounties. 

The exploit worked by manipulating Sovryn’s iToken price – interest-bearing tokens representing the share of cryptocurrency a user holds in a lending pool. This token’s price is updated every time a lending pool position is interacted with. 

How the Funds Were Drained

First, the attacker bought WRBTC (wrapped RBTC) using a flash swap in RskSwap. Then, he borrowed additional WRBTC from Sovryn’s lending contract using his own XUSD (another stablecoin) as collateral. 

“The attacker then provided liquidity to the RBTC lending contract, closed their loan with a swap using their XUSD collateral, redeemed (burned) their iRBTC token, and sent the WRBTC back to RskSwap to complete the flash swap,” the post continued. 

The entire process manipulated the iToken price such that the attacker could withdraw far more RBTC from the lending pool than was first deposited. 

Sovryn clarified that user funds have not been affected by the hack. Any missing value from the lending pools will be reinjected by Exchequer – the Sovryn treasury. 

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 0.000000
ethereum
Ethereum (ETH) $ 0.000000
tether
Tether (USDT) $ 0.000000
bnb
BNB (BNB) $ 0.000000
xrp
XRP (XRP) $ 0.000000
usd-coin
USDC (USDC) $ 0.000000
solana
Wrapped SOL (SOL) $ 0.000000
staked-ether
Lido Staked Ether (STETH) $ 0.000000
tron
TRON (TRX) $ 0.000000
dogecoin
Dogecoin (DOGE) $ 0.000000
cardano
Cardano (ADA) $ 0.000000
figure-heloc
Figure Heloc (FIGR_HELOC) $ 0.000000
whitebit
WhiteBIT Coin (WBT) $ 0.000000
wrapped-steth
Wrapped stETH (WSTETH) $ 0.000000
bitcoin-cash
Bitcoin Cash (BCH) $ 0.000000
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 0.000000
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 0.000000
usds
USDS (USDS) $ 0.000000
chainlink
Chainlink (LINK) $ 0.000000
wrapped-eeth
Wrapped eETH (WEETH) $ 0.000000
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.000000
leo-token
LEO Token (LEO) $ 0.000000
weth
WETH (WETH) $ 0.000000
hyperliquid
Hyperliquid (HYPE) $ 0.000000
monero
Monero (XMR) $ 0.000000
stellar
Stellar (XLM) $ 0.000000
zcash
Zcash (ZEC) $ 0.000000
ethena-usde
Ethena USDe (USDE) $ 0.000000
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 0.000000
litecoin
Litecoin (LTC) $ 0.000000
sui
Sui (SUI) $ 0.000000
avalanche-2
Avalanche (AVAX) $ 0.000000
hedera-hashgraph
Hedera (HBAR) $ 0.000000
shiba-inu
Shiba Inu (SHIB) $ 0.000000
susds
sUSDS (SUSDS) $ 0.000000
usdt0
USDT0 (USDT0) $ 0.000000
dai
Dai (DAI) $ 0.000000
mantle
Mantle (MNT) $ 0.000000
the-open-network
Toncoin (TON) $ 0.000000
world-liberty-financial
World Liberty Financial (WLFI) $ 0.000000
paypal-usd
PayPal USD (PYUSD) $ 0.000000
crypto-com-chain
Cronos (CRO) $ 0.000000
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 0.000000
uniswap
Uniswap (UNI) $ 0.000000
polkadot
Polkadot (DOT) $ 0.000000
memecore
MemeCore (M) $ 0.000000
aave
Aave (AAVE) $ 0.000000
bittensor
Bittensor (TAO) $ 0.000000
usd1-wlfi
USD1 (USD1) $ 0.000000
canton-network
Canton (CC) $ 0.000000
Shares