BonqDAO protocol suffers $120M loss after oracle hack

0

[ad_1]

A small decentralized autonomous organization (DAO) has suffered a rather sizeable smart contract exploit, leading to an estimated $120 million being stolen from its protocol.

BonqDAO told its Twitter followers on Feb. 1 that its Bonq protocol was exposed to an oracle hack that allowed the exploiter to manipulate the price of the AllianceBlock (ALBT) token.

An independent analysis from blockchain security firm PeckShield has estimated the loss from the Bonq hack to be around $120 million, comprising $108 million from 98.65 million BEUR tokens and $11 million from 113.8 million wrapped-ALBT (wALBT) tokens.

While the exploit took effect over several transactions, the largest was $82.19 million at 6:32 pm UTC time on Feb. 1, according to multichain portfolio tracker DeBank.

Most of the high-scale transactions took place on the Polygon network.

How it happened

PeckShield explained that the exploiter was able to change the updatePrice function of the oracle in one of BonqDAO’s smart contracts, which meant that they were able to manipulate the price of the wALBT token.

This triggered the exploitation of the wALBT and BEUR. The hacker then swapped about $500,000 worth of BEUR for USDC on Uniswap before burning all 113.8 million wALBT to unlock ALBT.

On-chain security observer “Spreek” — who was one of the first to spot the exploit — told his 18,800 Twitter followers that the exploiter later dumped more BEUR and ALBT tokens for $500,000 in USDC and 144 ETH ($236,000).

PeckShield and others noted that the price of the BEUR and ALBT tokens went down considerably in a short period of time:

In a follow up tweet, BonqDAO said it has paused the protocol and is working on a recovery solution.

“Other troves remain unaffected. Bonq protocol has been paused. We’re working on a solution that will allow users to withdraw all remaining collateral without repaying BEUR in the troves. It will be released tomorrow morning CET,” it said.

AllianceBlock — the token issuers of ALBT — also shared the news on Feb. 1, explaining to its 51,300 Twitter followers that an exploiter managed to gain access to 113.8 million ALBT tokens.

The team is in the process of removing all liquidity on Bonq and has halted exchange trading, it said, adding that no smart contracts were exploited on AllianceBlock.

The announcement from AllianceBlock also added that they would mint new ALBT tokens to those impacted by the exploit up until the time of the announcement.

Related: Tribe DAO votes in favor of repaying victims of $80M Rari hack

BonqDAO is a decentralized autonomous organization that aims to provide self-sovereign financial services to individuals and businesses interest-free without giving up ownership of their assets.

AllianceBlock is a decentralized infrastructure platform that connects traditional financial institutions to Web3 applications.



[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 87,981.00
ethereum
Ethereum (ETH) $ 2,956.81
tether
Tether (USDT) $ 0.999517
bnb
BNB (BNB) $ 847.72
xrp
XRP (XRP) $ 1.87
usd-coin
USDC (USDC) $ 0.999870
tron
TRON (TRX) $ 0.278391
staked-ether
Lido Staked Ether (STETH) $ 2,955.49
dogecoin
Dogecoin (DOGE) $ 0.128636
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.01
cardano
Cardano (ADA) $ 0.366896
whitebit
WhiteBIT Coin (WBT) $ 58.23
bitcoin-cash
Bitcoin Cash (BCH) $ 589.72
wrapped-steth
Wrapped stETH (WSTETH) $ 3,612.70
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 87,948.00
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,213.18
usds
USDS (USDS) $ 0.999960
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999448
wrapped-eeth
Wrapped eETH (WEETH) $ 3,204.86
chainlink
Chainlink (LINK) $ 12.45
monero
Monero (XMR) $ 438.67
weth
WETH (WETH) $ 2,955.30
zcash
Zcash (ZEC) $ 426.78
stellar
Stellar (XLM) $ 0.218043
leo-token
LEO Token (LEO) $ 7.37
hyperliquid
Hyperliquid (HYPE) $ 24.42
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 88,073.00
ethena-usde
Ethena USDe (USDE) $ 0.998780
litecoin
Litecoin (LTC) $ 76.32
sui
Sui (SUI) $ 1.43
avalanche-2
Avalanche (AVAX) $ 11.99
susds
sUSDS (SUSDS) $ 1.09
hedera-hashgraph
Hedera (HBAR) $ 0.110063
shiba-inu
Shiba Inu (SHIB) $ 0.000007
dai
Dai (DAI) $ 0.999641
usdt0
USDT0 (USDT0) $ 0.999555
paypal-usd
PayPal USD (PYUSD) $ 0.999096
mantle
Mantle (MNT) $ 1.16
world-liberty-financial
World Liberty Financial (WLFI) $ 0.130520
the-open-network
Toncoin (TON) $ 1.45
crypto-com-chain
Cronos (CRO) $ 0.092245
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
uniswap
Uniswap (UNI) $ 5.19
polkadot
Polkadot (DOT) $ 1.81
canton-network
Canton (CC) $ 0.076595
aave
Aave (AAVE) $ 181.83
usd1-wlfi
USD1 (USD1) $ 0.999287
rain
Rain (RAIN) $ 0.007769
memecore
MemeCore (M) $ 1.51
bitget-token
Bitget Token (BGB) $ 3.45
Shares