Curve Finance resolves site exploit, directs users to revoke any recent contracts

0

[ad_1]

On Aug 9, automated market maker Curve Finance took to Twitter to warn users of an exploit on its site. The team behind the protocol noted that the issue, which appeared to be an attack from a malicious actor, was affecting the service’s nameserver and frontend.

Curve stated via Twitter that its exchange — which is a separate product — appeared to be unaffected by the attack, as it uses a different DNS provider. 

However, the issue was quickly addressed by the team. An hour after the initial warning, Curve said it had both found and reverted the issue, directing users to have approved any contracts on Curve in the last few hours to revoke them “immediately.” 

Curve noted that most likely the domain name system (DNS) server provider ‘iwantmyname’ was hacked, adding that it has subsequently changed its nameserver. 

A nameserver works like a directory that translates domain names into IP addresses. 

While the exploit was ongoing, Twitter user LefterisJP speculated that the alleged attacker had likely utilized DNS spoofing to execute the exploit on the service:

Other participants in the DeFi space quickly took to Twitter to spread the warning to their own followers, with some noting that the alleged thief appears to have stolen more than $573K USD.

Back in July, analysts suggested that they were favorably eyeing Curve Finance, despite the market downturn which continues to affect the larger DeFi space. Among the reasons cited by researchers at Delphi Digital for their bullishness, they specifically called out the platform’s yield opportunities, the demand for CRV deposits, and the protocol’s revenue generation from stablecoin liquidity.

This followed the platform’s release of a new “algorithm for exchanging volatile assets” in June, which promised to allow low-slippage swaps between “volatile” assets. These pools use a combination of internal oracles relying on Exponential Moving Averages (EMAs) and a bonding curve model, previously deployed by popular AMMs such as Uniswap.

Update: Added announcement from Curve Finance that the issue has been resolved, pointing to its name server as the likely culprit for the exploit. 

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 87,047.32
ethereum
Ethereum (ETH) $ 2,806.36
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 2.02
bnb
BNB (BNB) $ 831.02
usd-coin
USDC (USDC) $ 1.00
tron
TRON (TRX) $ 0.277312
staked-ether
Lido Staked Ether (STETH) $ 2,806.27
dogecoin
Dogecoin (DOGE) $ 0.135635
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
cardano
Cardano (ADA) $ 0.389506
whitebit
WhiteBIT Coin (WBT) $ 57.87
wrapped-steth
Wrapped stETH (WSTETH) $ 3,426.51
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 86,935.29
bitcoin-cash
Bitcoin Cash (BCH) $ 522.28
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,040.31
usds
USDS (USDS) $ 0.999679
leo-token
LEO Token (LEO) $ 9.85
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
hyperliquid
Hyperliquid (HYPE) $ 31.67
chainlink
Chainlink (LINK) $ 12.13
weth
WETH (WETH) $ 2,807.59
stellar
Stellar (XLM) $ 0.232586
monero
Monero (XMR) $ 394.24
wrapped-eeth
Wrapped eETH (WEETH) $ 3,038.60
ethena-usde
Ethena USDe (USDE) $ 0.999566
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 87,087.33
litecoin
Litecoin (LTC) $ 78.03
hedera-hashgraph
Hedera (HBAR) $ 0.131842
avalanche-2
Avalanche (AVAX) $ 13.02
zcash
Zcash (ZEC) $ 327.15
sui
Sui (SUI) $ 1.35
shiba-inu
Shiba Inu (SHIB) $ 0.000008
dai
Dai (DAI) $ 0.999596
world-liberty-financial
World Liberty Financial (WLFI) $ 0.156250
susds
sUSDS (SUSDS) $ 1.07
paypal-usd
PayPal USD (PYUSD) $ 0.999852
crypto-com-chain
Cronos (CRO) $ 0.102174
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
usdt0
USDT0 (USDT0) $ 1.00
the-open-network
Toncoin (TON) $ 1.50
uniswap
Uniswap (UNI) $ 5.49
polkadot
Polkadot (DOT) $ 2.07
mantle
Mantle (MNT) $ 0.982370
canton-network
Canton (CC) $ 0.076319
usd1-wlfi
USD1 (USD1) $ 0.999551
aave
Aave (AAVE) $ 168.93
bittensor
Bittensor (TAO) $ 260.99
bitget-token
Bitget Token (BGB) $ 3.46
memecore
MemeCore (M) $ 1.38
Shares