How Someone Borrowed $1.6M With $70 Worth of Collateral: The Tender.Fi Exploit

0

[ad_1]

The hacker who stole $1.59 million worth of crypto assets from Arbitrum-based decentralized finance (DeFi) lending platform Tender.fi has returned nearly all the funds, keeping roughly $97,000 as a bounty reward.

Tender.fi was exploited on the morning of March 7, with the project’s official Twitter handle confirming the incident in a tweet a few minutes later.

Tender.fi Exploited for $1.59 Million

According to the tweet, Tender.fi disclosed that it had noticed and was looking into an “unusual amount” of loans. The platform also paused its lending service during the investigation.

On-chain data showed that the attacker exploited an oracle glitch. The bug allowed the hacker to borrow up to $1.59 million in ether (ETH) tokens with a deposit of one GMX token worth $71 as collateral.

After the exploit, the hacker left an on-chain message for Tender.fi, saying, “It looks like your oracle was misconfigured. contact me to sort this out.” This shows that the exploiter is a white hat hacker.

A few hours later, Tender.fi disclosed that it had contacted the attacker to negotiate and discuss the terms of a bounty agreement.

“The whitehat has made contact over debank and we are currently in discussions on how to remedy this situation. We will update you with more information when we have it,” the protocol said.

Hacker Keeps $97k as Bounty

Seven hours later, the protocol revealed that it had agreed with the hacker and the funds would be returned.

About an hour later, the hacker returned $1.49 million and kept $96,500 as a bounty. Both Tender.fi and blockchain security firm PeckShield confirmed the transaction.

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 62,930.00
ethereum
Ethereum (ETH) $ 1,649.67
tether
Tether (USDT) $ 0.998994
bnb
BNB (BNB) $ 599.17
usd-coin
USDC (USDC) $ 0.999732
xrp
XRP (XRP) $ 1.11
solana
Solana (SOL) $ 65.16
tron
TRON (TRX) $ 0.321853
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05
dogecoin
Dogecoin (DOGE) $ 0.084666
hyperliquid
Hyperliquid (HYPE) $ 56.24
usds
USDS (USDS) $ 0.999714
leo-token
LEO Token (LEO) $ 9.56
rain
Rain (RAIN) $ 0.013160
zcash
Zcash (ZEC) $ 424.68
wrapped-steth
Wrapped stETH (WSTETH) $ 2,779.67
monero
Monero (XMR) $ 348.48
canton-network
Canton (CC) $ 0.167671
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 76,243.00
stellar
Stellar (XLM) $ 0.188143
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
cardano
Cardano (ADA) $ 0.165466
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 2,466.93
whitebit
WhiteBIT Coin (WBT) $ 51.58
chainlink
Chainlink (LINK) $ 7.79
ethena-usde
Ethena USDe (USDE) $ 0.999013
wrapped-eeth
Wrapped eETH (WEETH) $ 2,465.31
the-open-network
Toncoin (TON) $ 1.64
usd1-wlfi
USD1 (USD1) $ 0.998588
susds
sUSDS (SUSDS) $ 1.08
dai
Dai (DAI) $ 0.999570
bitcoin-cash
Bitcoin Cash (BCH) $ 200.31
memecore
MemeCore (M) $ 2.88
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 76,366.00
hedera-hashgraph
Hedera (HBAR) $ 0.078399
litecoin
Litecoin (LTC) $ 42.49
sui
Sui (SUI) $ 0.747575
weth
WETH (WETH) $ 2,268.37
hashnote-usyc
Circle USYC (USYC) $ 1.13
paypal-usd
PayPal USD (PYUSD) $ 1.00
avalanche-2
Avalanche (AVAX) $ 6.55
usdt0
USDT0 (USDT0) $ 0.998824
shiba-inu
Shiba Inu (SHIB) $ 0.000005
crypto-com-chain
Cronos (CRO) $ 0.059818
lab
LAB (LAB) $ 9.02
global-dollar
Global Dollar (USDG) $ 0.999879
near
NEAR Protocol (NEAR) $ 2.01
audiera
Audiera (BEAT) $ 8.83
tether-gold
Tether Gold (XAUT) $ 4,071.84
Shares