DeFi Platform CoW Protocol Loses Over 550 BNB in Contract Exploit

0

[ad_1]

Decentralized finance (DeFi) protocol CoW Swap has suffered a smart contract exploit, leading to the loss of approximately 551 BNB ($181,600).

According to reports, the attacker added a wallet address as a “solver” of CoW Swap and invoked a transaction to approve DAI transfers to SwapGuard before moving the assets to other addresses.

A Settlement Contract Exploit

Blockchain surveyor MevRefund first noticed the attack in the early hours of today. The maximal extractable value (MEV) searcher tweeted that CoW Swap’s funds were being moved, adding that the protocol’s SwapGuard feature had been granted allowance and allowed anyone to make “arbitrary function calls.”

Within an hour, blockchain security firm PeckShield revealed that CoW Swap’s GPv2Settlement contract was tricked ten days ago, approving SwapGuard for DAI spending.

At the time of the exploit, the attacker just triggered the SwapGuard to transfer DAI out of the GPv2Settlement contract.

In a more detailed explanation, blockchain security platform BlockSec disclosed that the attacker had added a wallet address as a solver of the protocol by the multi-sig, hence, the ability to approve the transactions. Since the DAI transfer was approved from the settlement contract, the exploiter could also approve transfers to arbitrary addresses.

“A lesson learned. A contract with the interface of arbitrary call should not have any allowance, 0x55a37a2e5e5973510ac9d9c723aec213fa161919 made the mistake and approved the maximum value of DAI to SwapGuard, which is the root cause of the attack,” BlockSec said.

Over $181k Moved to Tornado Cash

Tokens transferred to the exploiter’s address include BNB, USDT, USDC, and ETH. So far, roughly 551 BNB worth over $181,000 has been moved to the OFAC-sanctioned crypto mixer Tornado Cash.

CoW Swap urged users not to worry, as the stolen funds were CoW Protocol’s accumulated fees from the past week. The platform said the issue has been mitigated and is currently under investigation.

CoW Protocol is the latest DeFi platform to suffer at the hands of daring hackers this month. CryptoPotato reported last week that Orion Protocol and BonqDAO were hacked, leading to the loss of $3 million and $10 million, respectively.

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 65,699.00
ethereum
Ethereum (ETH) $ 1,717.20
tether
Tether (USDT) $ 0.999341
bnb
BNB (BNB) $ 615.80
usd-coin
USDC (USDC) $ 0.999714
xrp
XRP (XRP) $ 1.18
solana
Solana (SOL) $ 71.24
tron
TRON (TRX) $ 0.319871
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.02
staked-ether
Lido Staked Ether (STETH) $ 2,265.05
hyperliquid
Hyperliquid (HYPE) $ 65.13
dogecoin
Dogecoin (DOGE) $ 0.088403
usds
USDS (USDS) $ 0.999644
leo-token
LEO Token (LEO) $ 9.80
rain
Rain (RAIN) $ 0.013511
zcash
Zcash (ZEC) $ 493.67
wrapped-steth
Wrapped stETH (WSTETH) $ 2,779.67
cardano
Cardano (ADA) $ 0.180586
canton-network
Canton (CC) $ 0.164759
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 76,243.00
stellar
Stellar (XLM) $ 0.189376
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
whitebit
WhiteBIT Coin (WBT) $ 53.39
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 2,466.93
monero
Monero (XMR) $ 333.02
chainlink
Chainlink (LINK) $ 8.18
the-open-network
Toncoin (TON) $ 1.80
wrapped-eeth
Wrapped eETH (WEETH) $ 2,465.31
ethena-usde
Ethena USDe (USDE) $ 0.999333
usd1-wlfi
USD1 (USD1) $ 0.999977
susds
sUSDS (SUSDS) $ 1.08
bitcoin-cash
Bitcoin Cash (BCH) $ 212.51
dai
Dai (DAI) $ 0.999783
memecore
MemeCore (M) $ 2.95
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 76,366.00
hedera-hashgraph
Hedera (HBAR) $ 0.081565
litecoin
Litecoin (LTC) $ 45.10
lab
LAB (LAB) $ 10.58
weth
WETH (WETH) $ 2,268.37
sui
Sui (SUI) $ 0.795434
near
NEAR Protocol (NEAR) $ 2.39
hashnote-usyc
Circle USYC (USYC) $ 1.13
usdt0
USDT0 (USDT0) $ 0.998824
shiba-inu
Shiba Inu (SHIB) $ 0.000005
avalanche-2
Avalanche (AVAX) $ 6.77
crypto-com-chain
Cronos (CRO) $ 0.061889
paypal-usd
PayPal USD (PYUSD) $ 0.999818
bittensor
Bittensor (TAO) $ 278.32
global-dollar
Global Dollar (USDG) $ 0.999912
tether-gold
Tether Gold (XAUT) $ 4,295.07
Shares