Rari Fuze hacker offered $10M bounty by Fei Protocol to return $80M loot

0

[ad_1]

Decentralized finance (DeFi) platform Fei Protocol offered a $10 million bounty to hackers in an attempt to negotiate and retrieve a major chunk of the stolen funds from various Rari Fuse pools worth $79,348,385.61 or nearly $80 million.

On April 30, Fei Protocol informed its investors about an exploit across numerous Rari Capital Fuse pools while requesting the hackers to return the stolen funds against a $10 million bounty and a ‘no questions asked’ commitment.

While the exact losses from the exploit were not officially released, DeFi investigator BlockSec’s monitoring system detected a loss of more than $80 million — citing the root cause as a typical reentrancy vulnerability. While reentrancy bugs have been the main culprit in many exploits within the DeFi ecosystem, the $80 million loot makes the Fei Protocol exploit one of the largest reentrancy hacks ever.

Invocation flow. Source: BlockSec

Upon further investigations, Rari developer Jack Longarzo revealed a total of six vulnerable pools (8, 18, 27, 127, 144, 146, 156) that have been temporarily paused while an internal fix is underway. At the time of writing, Rari’s internal and external security engineers partnered with DeFi service provider Compound Treasury to further investigate and neutralize the hack.

Providing further insights into the development, blockchain investigator PeckShield narrowed down the exploit to a reentrancy bug, which allows hackers to use a function and make external calls to another untrusted contract.

Security-focused ranking platform CertiK told Cointelegraph that the attacker has sent 5400 Ether (ETH) (~$15,298,900) to Tornado Cash and still holds $64,245,245.43 (22,672.97 ETH) in their wallet. The attack has drained funds from the Rari pool whilst the Fei Pools (Tribe, Curve) remain unaffected.

Last year, in May 8, 2021, Rari Capital became victim to a high-priced exploit that was related to an integration with Alpha Venture DAO (previously Alpha Finance Lab). At the time of reporting, there have been no official announcements from the Fei Protocol team on the results of their investigation.

Related: Plan for $1M bug bounties and double the nodes in wake of $600M Ronin hack

As the crypto community goes through an ever evolving battle against hackers, numerous projects and protocols have decided to amp up their security measures. On April 28, the Ronin Network and Sky Mavis revealed plans to upgrade their smart contracts — following the $600 million hack in the previous month.

The Federal Bureau of Investigation (FBI) attributed the attack to North Korea-based and state-sponsored hacking group Lazurus, as it fired off a warning to other crypto and blockchain organizations.



[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 66,410.00
ethereum
Ethereum (ETH) $ 1,816.19
tether
Tether (USDT) $ 0.999500
bnb
BNB (BNB) $ 619.35
xrp
XRP (XRP) $ 1.25
usd-coin
USDC (USDC) $ 0.999788
solana
Solana (SOL) $ 74.47
tron
TRON (TRX) $ 0.319839
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05
hyperliquid
Hyperliquid (HYPE) $ 67.57
dogecoin
Dogecoin (DOGE) $ 0.088766
usds
USDS (USDS) $ 0.999747
leo-token
LEO Token (LEO) $ 9.76
zcash
Zcash (ZEC) $ 520.34
rain
Rain (RAIN) $ 0.013787
wrapped-steth
Wrapped stETH (WSTETH) $ 2,779.67
stellar
Stellar (XLM) $ 0.217661
monero
Monero (XMR) $ 368.98
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 76,243.00
cardano
Cardano (ADA) $ 0.180366
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
whitebit
WhiteBIT Coin (WBT) $ 54.61
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 2,466.93
canton-network
Canton (CC) $ 0.165974
chainlink
Chainlink (LINK) $ 8.36
the-open-network
Gram (prev. Toncoin) (GRAM) $ 1.75
wrapped-eeth
Wrapped eETH (WEETH) $ 2,465.31
bitcoin-cash
Bitcoin Cash (BCH) $ 225.52
susds
sUSDS (SUSDS) $ 1.08
ethena-usde
Ethena USDe (USDE) $ 0.999475
usd1-wlfi
USD1 (USD1) $ 1.00
dai
Dai (DAI) $ 0.999752
memecore
MemeCore (M) $ 2.91
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 76,366.00
hedera-hashgraph
Hedera (HBAR) $ 0.082711
litecoin
Litecoin (LTC) $ 45.73
sui
Sui (SUI) $ 0.798960
weth
WETH (WETH) $ 2,268.37
near
NEAR Protocol (NEAR) $ 2.44
hashnote-usyc
Circle USYC (USYC) $ 1.13
lab
LAB (LAB) $ 9.72
usdt0
USDT0 (USDT0) $ 0.998824
shiba-inu
Shiba Inu (SHIB) $ 0.000005
avalanche-2
Avalanche (AVAX) $ 6.88
crypto-com-chain
Cronos (CRO) $ 0.062558
paypal-usd
PayPal USD (PYUSD) $ 0.999970
global-dollar
Global Dollar (USDG) $ 0.999982
tether-gold
Tether Gold (XAUT) $ 4,289.57
bittensor
Bittensor (TAO) $ 266.23
Shares