Fortress Protocol Hacked for $3 Million, Drained of All Funds

0

[ad_1]

Fortress Protocol – an algorithmic money market and defi lending protocol – has been drained of all funds following an oracle manipulation attack. The stolen crypto has since been bridged from Binance Smart Chain to Ethereum and mixed using the privacy protocol Tornado Cash.

Buying Out the Protocol

Blockchain security firm CertiK shared information about the hack with CryptoPotato on Monday. It began with the hacker using ETH to purchase a substantial amount of FTS – the governance token managing the FTS protocol.

The quorum votes on Fortress loans’ governance contract is 400,000 FTS. That was worth just $18,000 at the time of the hack and represented a smaller number of tokens than the attacker held. In other words, he now held the authority to pass any protocol change proposal that he liked.

As such, he passed proposal ID 11, which changed the collateral factor on FTS tokens within loan contracts from 0 to 700,000,000,000,000,000. He also updated the price oracle used by the loan contract such that the token’s price would update, even if voting power was zero.

“With these updates, the value of the attacker’s collateral (FTS) was raised significantly, so the attacker was able to borrow large amounts of other tokens from the loan contracts,” explained CertiK over Twitter.

The attacker used his remaining FTS to borrow a massive number of tokens, and convert them to over 1000 ETH, and over 400,000 DAI – worth over $3 million at the time of the hack. He then deployed a self-destruct mechanism encoded into his malicious smart contract and swiftly transferred the stolen goods to Tornado Cash.

The fortress protocol team said they are “absolutely devastated” by yesterday’s events. They have called on the community to not deposit any assets into Fortress, and for all available partners to assist in reclaiming the funds.

Tornado Cash: Criminal Tool of Choice

Both the ETH required to purchase the hacker’s initial FTS, and the ETH representing the hacker’s stolen goods came and went through Tornado Cash. The mixing protocol breaks the link between a sender and receiver’s address on Ethereum, letting the hacker keep his identity concealed from start to finish.

The same protocol has been useful to numerous crypto thieves over the past few months. The person or group behind the $600 million Ronin hack in March is now solely responsible for 15% of funds being deposited into the mixer.

In January, an approximate $14.6 million in ETH stolen from Crypto.com was laundered through Tornado.

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 64,964.00
ethereum
Ethereum (ETH) $ 1,756.67
tether
Tether (USDT) $ 0.999072
bnb
BNB (BNB) $ 609.86
usd-coin
USDC (USDC) $ 0.999788
xrp
XRP (XRP) $ 1.20
solana
Solana (SOL) $ 72.22
tron
TRON (TRX) $ 0.320176
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04
staked-ether
Lido Staked Ether (STETH) $ 2,265.05
hyperliquid
Hyperliquid (HYPE) $ 71.20
dogecoin
Dogecoin (DOGE) $ 0.086159
usds
USDS (USDS) $ 0.999703
leo-token
LEO Token (LEO) $ 9.65
rain
Rain (RAIN) $ 0.014039
zcash
Zcash (ZEC) $ 483.62
wrapped-steth
Wrapped stETH (WSTETH) $ 2,779.67
stellar
Stellar (XLM) $ 0.226614
monero
Monero (XMR) $ 340.73
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 76,243.00
whitebit
WhiteBIT Coin (WBT) $ 53.38
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
canton-network
Canton (CC) $ 0.162993
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 2,466.93
cardano
Cardano (ADA) $ 0.169131
chainlink
Chainlink (LINK) $ 8.17
usd1-wlfi
USD1 (USD1) $ 1.00
wrapped-eeth
Wrapped eETH (WEETH) $ 2,465.31
ethena-usde
Ethena USDe (USDE) $ 0.999176
the-open-network
Gram (prev. Toncoin) (GRAM) $ 1.65
susds
sUSDS (SUSDS) $ 1.08
bitcoin-cash
Bitcoin Cash (BCH) $ 213.09
dai
Dai (DAI) $ 0.999614
lab
LAB (LAB) $ 13.10
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 76,366.00
memecore
MemeCore (M) $ 3.03
hedera-hashgraph
Hedera (HBAR) $ 0.080729
litecoin
Litecoin (LTC) $ 45.26
weth
WETH (WETH) $ 2,268.37
sui
Sui (SUI) $ 0.790281
hashnote-usyc
Circle USYC (USYC) $ 1.13
near
NEAR Protocol (NEAR) $ 2.31
usdt0
USDT0 (USDT0) $ 0.998824
avalanche-2
Avalanche (AVAX) $ 6.84
shiba-inu
Shiba Inu (SHIB) $ 0.000005
global-dollar
Global Dollar (USDG) $ 1.00
paypal-usd
PayPal USD (PYUSD) $ 0.999941
crypto-com-chain
Cronos (CRO) $ 0.059456
tether-gold
Tether Gold (XAUT) $ 4,308.54
bittensor
Bittensor (TAO) $ 253.81
Shares